Executive brief
Google Chrome is a widely used web browser. A vulnerability in its XML processing component could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or be used as part of a larger attack to compromise the system.
Technical details
A use-after-free (UAF) vulnerability exists in the XML parsing component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of XML content within a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (ACE) within the context of the browser's sandbox. This vulnerability is tracked as CWE-416. Google has addressed this issue in version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: CVE published to NVD