Executive brief
Google Chrome is a widely used web browser. A vulnerability in its media handling component could allow a remote attacker to access sensitive information from the computer's memory. To exploit this, an attacker would first need to compromise the browser's rendering process, typically by tricking a user into visiting a specially crafted website.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Media component of Google Chrome for Windows prior to version 151.0.7922.72. The flaw allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. A successful exploit requires the attacker to have already achieved code execution within a compromised renderer process. This vulnerability was reported by Google and is addressed in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-03: disclosed: Reported to Chromium project
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory: NVD publication date