Executive brief
Google Chrome, a widely used web browser, contains a security vulnerability in its Loader component. An attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code on the user's computer, though the impact is limited by the browser's security sandbox.
Technical details
A use-after-free (UAF) vulnerability exists in the Loader component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the loading of web content, allowing a remote attacker to achieve arbitrary code execution (ACE) within the renderer sandbox. Exploitation requires a user to navigate to a malicious HTML page. The vulnerability was addressed in version 151.0.7922.72 for Windows, Mac, and Linux. Google has assigned this a 'High' severity rating.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-03-29: disclosed: Reported to Chromium by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date