Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebAudio component, which handles sound processing, could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited to the browser's security sandbox, it represents a significant risk to user data and system integrity.
Technical details
This vulnerability stems from an 'inappropriate implementation' within the WebAudio component of the Chromium engine. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the browser's sandbox. The issue was triaged by the Chromium team with a 'High' severity rating. Users are advised to update to version 150.0.7871.182 or later.
Affected products
- Google Chrome Prior to 150.0.7871.182
Timeline
- 2026-06-26: other: Vulnerability triaged by Chromium team
- 2026-07-21: patched: Fixed in version 150.0.7871.182 for Windows/Mac and 150.0.7871.181 for Linux
- 2026-07-21: advisory: NVD publication date