Executive brief
A vulnerability in Google Chrome's document processing component could allow a remote attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website, potentially leading to unauthorized access to data or system compromise within the browser's security boundaries. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
A use-after-free (UAF) vulnerability exists in the Document Object Model (DOM) component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for DOM objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious HTML page, a remote attacker can exploit this condition to achieve arbitrary code execution within the browser's sandbox. The vulnerability was addressed in version 148.0.7778.179 for Windows and Mac, and 148.0.7778.178 for Linux.
Affected products
- Google Chrome Prior to 148.0.7778.179
Timeline
- 2026-03-25: other: Reported to Chrome by Google researchers
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: disclosed: CVE published