Executive brief
A security vulnerability in Google Chrome's accessibility features could allow an attacker to bypass the browser's security sandbox. If a user visits a specially crafted malicious website, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system. This could lead to unauthorized data access or the execution of malicious code outside the restricted browser environment.
Technical details
A use-after-free (UAF) vulnerability exists in the Accessibility component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. By exploiting this memory corruption issue, a remote attacker can achieve a sandbox escape, moving from the restricted renderer process to the more privileged browser process or the host operating system. The vulnerability was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
- 2026-05-28: disclosed: CVE published to NVD