Low chrome UAF 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactUse after free in Input
DescriptionUse after free in Input
ComponentInput
Bug ClassUAF
Tracker502362260
Fix commit4e44357a9f99 (chromium/src) +5/-0
CISA KEVNot listed
CreditedWeipeng Jiang (@Krace) of VRI
Disclosed2026-06-02

Changed Functions

FunctionChangeNotes
if
components/input/passthrough_touch_event_queue.cc
modified

Files Changed

  • components/input/passthrough_touch_event_queue.cc
From 4e44357a9f99e3839f109f7a84150555202ce04c Mon Sep 17 00:00:00 2001
From: Takashi Sakamoto <[email protected]>
Date: Fri, 17 Apr 2026 00:18:12 -0700
Subject: [PATCH] Make PassthroughTouchEventQueue weakable to see whether `this` is destroyed or not inside FlashQueue().

PassthroughTouchEventQueue::AckCompletedEvents() synchronously invokes
neste d message loop and the message loop may invoke some method which
destroys the PassthroughTouchEventQueue instance. This is
heap-use-after-free.

Bug: 502362260
Change-Id: I559bfc6be52ac68c0d17ce834da1384e4e173ba8
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7765950
Owners-Override: Keishi Hattori <[email protected]>
Reviewed-by: Keishi Hattori <[email protected]>
Commit-Queue: Takashi Sakamoto <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1616370}
---

diff --git a/components/input/passthrough_touch_event_queue.cc b/components/input/passthrough_touch_event_queue.cc
index 94686c1..b8a243c 100644
--- a/components/input/passthrough_touch_event_queue.cc
+++ b/components/input/passthrough_touch_event_queue.cc
@@ -246,6 +246,8 @@
   base::AutoReset<bool> process_acks(&processing_acks_, true);
   drop_remaining_touches_in_sequence_ = true;
   client_->FlushDeferredGestureQueue();
+  base::WeakPtr<PassthroughTouchEventQueue> weak_this =
+      weak_ptr_factory_.GetWeakPtr();
   while (!outstanding_touches_.empty()) {
     auto iter = outstanding_touches_.begin();
     TouchEventWithLatencyInfoAndAckState event = *iter;
@@ -255,6 +257,9 @@
           blink::mojom::InputEventResultSource::kBrowser,
           blink::mojom::InputEventResultState::kNoConsumerExists);
     AckTouchEventToClient(event, event.ack_source(), event.ack_state());
+    if (!weak_this) {
+      return;  // Object was destroyed during the ACK, bail out safely.
+    }
   }
 }
 
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.