Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Document Object Model (DOM) component—the system that processes website structure—could allow a malicious website to corrupt the browser's memory. If exploited, this could lead to browser crashes or potentially allow an attacker to execute unauthorized code on a user's device.
Technical details
A heap corruption vulnerability exists in the Document Object Model (DOM) implementation of Google Chrome. The flaw stems from insufficient data validation or an inappropriate implementation when processing HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to memory corruption, potentially allowing for arbitrary code execution within the browser's sandbox. The issue was addressed in Chrome version 150.0.7871.115.
Affected products
- Google Chrome prior to 150.0.7871.115
Timeline
- 2026-06-14: disclosed: Reported to Google internally
- 2026-07-08: patched: Fixed in stable channel update 150.0.7871.115
- 2026-07-08: advisory