Executive brief
A security vulnerability has been identified in Google Chrome for Mac that could allow an attacker to bypass the browser's security sandbox. This sandbox is designed to prevent malicious websites from accessing the rest of your computer. If exploited, an attacker who has already gained control over a web page's rendering process could potentially gain broader access to the underlying operating system, leading to data theft or unauthorized system control.
Technical details
A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during GPU operations, allowing a remote attacker to exploit a previously freed memory location. To successfully exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, the attacker can use a specially crafted HTML page to trigger the UAF in the GPU process, potentially leading to a sandbox escape and arbitrary code execution on the host system. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72 for Mac
- 2026-07-30: disclosed: NVD publication date