Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebGL component, which handles 3D graphics, could allow a malicious website to read sensitive information from the browser's memory. This could potentially lead to the exposure of data from other open tabs or internal browser processes if a user visits a specially crafted webpage.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the WebGL component of Google Chrome prior to version 151.0.7922.72. The flaw is triggered when the browser processes a specially crafted HTML page containing malicious WebGL instructions. A remote, unauthenticated attacker can exploit this to read memory outside of the intended buffer, potentially leading to information disclosure. This vulnerability is categorized by Chromium developers as Medium severity. Users are advised to update to version 151.0.7922.72 or later to mitigate the risk.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory