Executive brief
A security vulnerability exists in Google Chrome for Windows that could allow a malicious website to bypass the browser's security sandbox. This occurs when the browser incorrectly handles memory related to media processing. If an attacker has already compromised the browser's rendering engine, they could use this flaw to gain broader access to the underlying operating system, potentially leading to unauthorized data access or system control.
Technical details
A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome for Windows. The flaw is triggered when the browser attempts to access memory that has already been freed, specifically during the processing of media content. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption to escape the sandbox and execute arbitrary code on the host system. The vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome Prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date