Executive brief
A vulnerability in Google Chrome's user interface component could allow a remote attacker to bypass security protections. By convincing a user to visit a specially crafted website, an attacker who has already compromised the browser's rendering process could escape the security 'sandbox' that normally isolates web pages from the rest of the computer. This could lead to unauthorized access to the underlying operating system and sensitive user data.
Technical details
A use-after-free (UAF) vulnerability exists in the User Interface (UI) component of Google Chrome. The flaw is triggered when the browser incorrectly manages the lifecycle of UI objects, allowing an attacker to reference memory after it has been freed. To exploit this, a remote attacker must first compromise the renderer process (e.g., via a separate vulnerability) and then use a crafted HTML page to trigger the UAF in the browser process. Successful exploitation allows for a sandbox escape, granting the attacker the ability to execute arbitrary code with the privileges of the browser process. The issue is resolved in Google Chrome version 148.0.7778.168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-14: disclosed: CVE published to the NVD.