Executive brief
A vulnerability in Google Chrome's input handling component could allow a malicious website to break out of the browser's security sandbox. This type of flaw is serious because it allows an attacker who has already gained a foothold in the browser to access the underlying operating system and user data. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome prior to version 148.0.7778.216. The flaw is triggered when the browser incorrectly manages memory during the processing of input events. An attacker who has already compromised the renderer process can exploit this issue via a specially crafted HTML page to achieve a sandbox escape. This would allow the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. Google has addressed this in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop versions.
- 2026-05-28: disclosed: CVE published to NVD.