Executive brief
A critical vulnerability has been identified in Google Chrome's Views component, which handles the browser's user interface elements. If a user visits a specially crafted malicious website, an attacker who has already compromised the browser's rendering process could bypass security boundaries (the sandbox) that normally isolate the browser from the rest of the computer. This could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome. The flaw is reachable via a crafted HTML page. An attacker who has already achieved remote code execution within the sandboxed renderer process can leverage this memory corruption bug to perform a sandbox escape. This would allow the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-02: disclosed: Reported to Google
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date