Executive brief
Google Chrome is a widely used web browser for accessing the internet. A critical vulnerability was found that allows a malicious website to execute unauthorized code on a user's computer if they visit a specially crafted page. This could lead to a complete compromise of the user's system, including the theft of sensitive data or the installation of malware.
Technical details
A use-after-free vulnerability exists in the 'Base' component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content, allowing a remote attacker to potentially execute arbitrary code in the context of the browser process. An attacker would need to entice a user to visit a malicious website to exploit this vulnerability. The issue is resolved in version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-04-25: disclosed: Reported by Google researchers
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: advisory: NVD publication date