Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its graphics processing unit (GPU) component. An attacker who has already partially compromised the browser's internal rendering process could exploit this flaw to steal sensitive data from other websites the user is visiting. This could lead to the exposure of private information across different web domains, though it requires the attacker to first gain a foothold through a separate vulnerability.
Technical details
A vulnerability classified as an 'inappropriate implementation' exists in the GPU process of Google Chrome. The flaw allows for cross-origin data leakage, effectively bypassing certain site isolation protections. To exploit this, a remote attacker must first achieve code execution within a compromised renderer process (a 'sandbox escape' or similar precondition). Once the renderer is compromised, the attacker can use a specially crafted HTML page to interact with the GPU component and extract data belonging to other origins. Google has addressed this in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Desktop version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date