Executive brief
Google Chrome for Mac is vulnerable to a security flaw within its browser extension system. If a user is tricked into installing a malicious extension, an attacker can execute unauthorized code on the user's computer. This could lead to the theft of sensitive data, unauthorized access to accounts, or full system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the Extensions component of Google Chrome for macOS. The flaw is triggered when the browser attempts to access memory that has already been freed, specifically during the processing of a crafted Chrome Extension. To exploit this, an attacker must use social engineering to convince a user to install a malicious extension. Successful exploitation allows the attacker to achieve arbitrary code execution (RCE) within the context of the browser. The issue is addressed in Chrome version 148.0.7778.168 for Mac.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Chrome Stable Channel Update released version 148.0.7778.168
- 2026-05-14: disclosed: NVD publication date