Executive brief
A critical vulnerability has been identified in the Google Chrome web browser's proxy handling component. By convincing a user to use a specially crafted Proxy Auto-Config (PAC) script, a remote attacker could execute malicious code on the user's computer. This could lead to a total compromise of the affected system, including the theft of sensitive data or the installation of malware.
Technical details
A use-after-free vulnerability exists in the Proxy component of Google Chrome. The flaw is triggered when the browser processes a maliciously crafted Proxy Auto-Config (PAC) script. An attacker can exploit this memory corruption vulnerability to achieve remote code execution (RCE) within the context of the browser process. The vulnerability is resolved in version 148.0.7778.216 and later. While the advisory lists the severity as 'info' in some metadata, Chromium's internal assessment classifies this as 'Critical' due to the potential for arbitrary code execution.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Desktop
- 2026-05-28: disclosed: CVE published to NVD dataset