Executive brief
A vulnerability has been identified in Google Chrome's V8 engine, which is responsible for processing JavaScript. An attacker who has already partially compromised the browser's rendering process could use this flaw to access sensitive information from the computer's memory. This could lead to the exposure of private data while a user is browsing a specially crafted website.
Technical details
This vulnerability is a use-after-free (UAF) class flaw located within the V8 JavaScript engine component of Google Chrome. The issue arises when the engine attempts to access memory that has already been freed, leading to potential out-of-bounds memory access. An attacker must first achieve a compromise of the renderer process (e.g., via a separate vulnerability) to exploit this flaw. Once the renderer is compromised, the attacker can use a crafted HTML page to trigger the UAF condition. This vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date