Executive brief
A critical security vulnerability was identified in Google Chrome's XR (Extended Reality) component on Windows. This flaw could allow a malicious website to break out of the browser's security sandbox, potentially gaining full control over the underlying operating system. Users are advised to update to version 148.0.7778.216 or later to protect their data and systems from unauthorized access.
Technical details
A use-after-free (UAF) vulnerability exists in the XR (Extended Reality) component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of crafted HTML content. An attacker who has already compromised the renderer process can exploit this memory corruption to escape the Chrome sandbox and execute arbitrary code on the host system. This vulnerability is rated as Critical by Chromium and was addressed in version 148.0.7778.216.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows
- 2026-05-28: disclosed: CVE published to NVD dataset