Executive brief
A security vulnerability exists in Google Chrome's Extended Reality (XR) component on Windows. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the user's computer or execute unauthorized commands. This could lead to the theft of sensitive data or a complete compromise of the affected system.
Technical details
A use-after-free (UAF) vulnerability exists in the XR (Extended Reality) component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of XR-related content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the browser process. Google has addressed this issue in version 148.0.7778.179 for Windows.
Affected products
- Google Chrome Prior to 148.0.7778.179
Timeline
- 2026-04-14: other: Reported to Google
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: advisory: NVD publication date