Executive brief
A security vulnerability in Google Chrome for Mac could allow a malicious browser extension to take control of a user's computer. If a user is tricked into installing a specifically crafted extension, an attacker could execute arbitrary commands and access sensitive data. This issue affects the Bluetooth component of the browser on macOS systems.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome for macOS (CWE-416). The flaw is triggered when the browser incorrectly manages memory during Bluetooth operations, which can be exploited by a malicious Chrome Extension. An attacker who successfully convinces a user to install a crafted extension can leverage this memory corruption to execute arbitrary code with the privileges of the browser process. The vulnerability was addressed in Chrome version 148.0.7778.216 for Mac.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD