Executive brief
A security vulnerability has been identified in Google Chrome for macOS that could allow a malicious website to compromise a user's computer. By tricking a user into visiting a specially crafted webpage, an attacker could potentially cause the browser to crash or execute unauthorized code. This issue affects the 'Views' component, which is responsible for rendering parts of the browser's user interface.
Technical details
A use-after-free vulnerability exists in the Views component of Google Chrome for macOS. The flaw is triggered when the browser attempts to access memory that has already been deallocated, typically during the processing of a specially crafted HTML page. A remote, unauthenticated attacker can exploit this to cause heap corruption, potentially leading to arbitrary code execution within the browser's sandbox or a denial-of-service (browser crash). The vulnerability is addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed