Executive brief
A vulnerability exists in Google Chrome's Autofill feature, which automatically completes forms for users. A remote attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute malicious code on the user's computer, though the impact is limited by the browser's security sandbox.
Technical details
A use-after-free (UAF) vulnerability exists in the Autofill component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of form fields on a web page. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page that, when rendered by a victim, triggers the memory corruption. This allows for arbitrary code execution within the context of the Chrome sandbox. The issue is resolved in version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-27: disclosed: Reported to Chromium project by Google researchers
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date