Executive brief
A security vulnerability exists in Google Chrome's Glic component that could allow an attacker to execute malicious code on a user's computer. By tricking a user into visiting a specially crafted website, an attacker could potentially gain control over the browser's processes. While the exploit is limited by the browser's security sandbox, it represents a significant risk to data privacy and system integrity.
Technical details
A use-after-free (UAF) vulnerability exists in the Glic component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle during the processing of specific web content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page, leading to arbitrary code execution within the context of the browser's sandbox. Google has addressed this issue in version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD