Executive brief
A security vulnerability exists in Google Chrome for macOS that could allow a malicious website to corrupt the browser's memory. To trigger the issue, an attacker must trick a user into visiting a specifically crafted webpage and performing certain mouse or keyboard actions. If successful, this could allow the attacker to crash the browser or potentially run unauthorized code on the user's computer.
Technical details
A use-after-free (UAF) vulnerability exists in the WebAppInstalls component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during the installation or handling of web applications. A remote attacker can exploit this by hosting a malicious HTML page and inducing the user to perform specific UI gestures, leading to heap corruption. This memory corruption can be leveraged to achieve arbitrary code execution within the context of the browser process. The issue is resolved in version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date