Executive brief
Google Chrome, a widely used web browser, was found to have a security vulnerability in its XML processing library. An attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code on the user's device, though the impact is limited by the browser's security sandbox.
Technical details
An integer overflow vulnerability (CWE-190) exists in the libxml library as integrated into Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page or XML content. A remote, unauthenticated attacker can leverage this overflow to achieve arbitrary code execution within the context of the Chrome renderer process sandbox. The vulnerability was reported by ebassi of Igalia and is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-04: disclosed: Reported to Chromium by ebassi of Igalia
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date