Executive brief
Google Chrome is a widely used web browser. A vulnerability in its data handling component could allow a malicious website to break out of the browser's security sandbox. If successful, an attacker who has already gained a foothold in the browser's rendering process could potentially gain broader access to the underlying Windows operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the DataTransfer component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during data transfer operations, such as drag-and-drop or copy-paste actions. A remote attacker who has already compromised the renderer process can exploit this issue via a specially crafted HTML page to achieve a sandbox escape. This would allow the attacker to execute code outside of the restricted browser environment on the host Windows system. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-28: disclosed: Reported to Google
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date