Executive brief
A security vulnerability exists in Google Chrome for Windows that could allow an attacker to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted website, an attacker who has already gained limited control over the browser's rendering process could escalate their access to the underlying operating system. This could lead to unauthorized data access or the execution of malicious software on the user's computer.
Technical details
A use-after-free (UAF) vulnerability exists in the User Interface (UI) component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during UI interactions, specifically after a renderer process has already been compromised. An attacker can exploit this by directing a user to a crafted HTML page, leveraging the compromised renderer to trigger the UAF condition in the browser's higher-privilege UI process. This sequence allows for a sandbox escape, potentially granting the attacker the ability to execute arbitrary code with the privileges of the logged-in user. The issue is resolved in version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE published to the NVD.