Low chrome UAF 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactUse after free in DevTools
DescriptionUse after free in DevTools
ComponentDevTools
Bug ClassUAF
Tracker513208773
Fix commite4ca88385f1d (chromium/src) +5/-1
CISA KEVNot listed
CreditedGoogle
Disclosed2026-06-30

Files Changed

  • third_party/blink/renderer/core/exported/web_dev_tools_agent_impl.cc
From e4ca88385f1d69e674f17ddf2ce89ee4e71a8db9 Mon Sep 17 00:00:00 2001
From: Simon Zünd <[email protected]>
Date: Tue, 26 May 2026 20:54:47 -0700
Subject: [PATCH] Snapshot WebViewImpl instances before iterating in WebDevToolsAgentImpl.

Iterating over WebViewImpl::AllInstances() while calling
NotifyPopupOpeningObservers() is unsafe because the observer
notification can synchronously create new WebViewImpl instances (e.g.,
via window.open()), invalidating the iterator. Copy the instances to a
HashSet first to ensure safe iteration.

Fixed: 513208773
Change-Id: Ic4ff7c1dc8e5c5bef2cbb5899692bc5973ba37dd
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7872315
Reviewed-by: Philip Rogers <[email protected]>
Commit-Queue: Simon Zünd <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1636683}
---

diff --git a/third_party/blink/renderer/core/exported/web_dev_tools_agent_impl.cc b/third_party/blink/renderer/core/exported/web_dev_tools_agent_impl.cc
index b8ab061a..e65bcb0 100644
--- a/third_party/blink/renderer/core/exported/web_dev_tools_agent_impl.cc
+++ b/third_party/blink/renderer/core/exported/web_dev_tools_agent_impl.cc
@@ -258,7 +258,11 @@
     CHECK(!input_events_disabler_);
     input_events_disabler_ =
         std::make_unique<ScopedInputEventsDisabler>(*frame);
-    for (auto* const view : WebViewImpl::AllInstances())
+    // NotifyPopupOpeningObservers() can run author scripts which can
+    // synchronously create a new WebViewImpl (e.g. via window.open()),
+    // mutating AllInstances() and invalidating the iterator. Snapshot first.
+    const HashSet<WebViewImpl*> instances = WebViewImpl::AllInstances();
+    for (auto* const view : instances)
       view->GetChromeClient().NotifyPopupOpeningObservers();
 
     // 2. Disable active objects
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.