Executive brief
Google Chrome is a widely used web browser. A vulnerability was identified in the 'Variations' component, which handles experimental feature configurations. An attacker positioned on a privileged network (such as a public Wi-Fi or a compromised corporate network) could send malicious traffic to trigger memory corruption in the browser, potentially leading to application crashes or unauthorized code execution.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Variations component of Google Chrome. The flaw stems from insufficient validation of data received over the network, which can lead to heap corruption. An attacker with a privileged network position (Man-in-the-Middle) could intercept or inject malicious network traffic to exploit this memory safety issue. Successful exploitation could lead to a denial of service or potentially arbitrary code execution within the browser process. The issue is resolved in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed