Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its networking component could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or be used as part of a larger attack to compromise the system.
Technical details
A use-after-free vulnerability exists in the Network component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during network operations, which can be exploited by a remote attacker who convinces a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. Google has addressed this issue in version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD