Executive brief
A security vulnerability exists in Google Chrome's Aura windowing system. By tricking a user into performing specific mouse or touch gestures on a malicious webpage, an attacker could potentially take control of the user's computer. This could lead to the theft of personal data or the installation of unauthorized software.
Technical details
A use-after-free (UAF) vulnerability exists in Aura, the windowing and event-handling framework for Google Chrome. The flaw is triggered when a user is convinced to engage in specific UI gestures while visiting a malicious HTML page. This memory corruption issue allows a remote attacker to potentially achieve arbitrary code execution (ACE) within the context of the browser process. The vulnerability is tracked as CWE-416 and was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE published to NVD.