Executive brief
A security vulnerability exists in Google Chrome's implementation of the QUIC network protocol. A remote attacker could exploit this flaw by sending malicious network traffic to a user's browser, potentially allowing them to execute unauthorized code. While the exploit is limited by the browser's security sandbox, it could still lead to data theft or further system compromise if combined with other vulnerabilities.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the QUIC networking component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of QUIC network packets. A remote, unauthenticated attacker can exploit this by delivering specially crafted network traffic, leading to arbitrary code execution within the context of the browser's sandbox. The vulnerability affects versions prior to 148.0.7778.179. Users are advised to update to the latest stable channel release to mitigate this risk.
Affected products
- Google Chrome prior to 148.0.7778.179
Timeline
- 2026-03-24: other: Reported by Google internal researchers
- 2026-05-19: patched: Fixed in Stable Channel Update 148.0.7778.178/179
- 2026-05-20: advisory: NVD publication date