Executive brief
A critical security vulnerability has been identified in Google Chrome's Ozone component, which handles low-level graphics and input. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass the browser's security sandbox. If successful, this could lead to unauthorized access to the underlying operating system and the user's private data.
Technical details
A use-after-free vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of crafted HTML content. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious webpage, leading to memory corruption. This corruption can be leveraged to achieve a sandbox escape, allowing for arbitrary code execution outside of the restricted browser environment. Google has addressed this issue in version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-14: disclosed: Reported to Chromium by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date