Executive brief
A vulnerability in Google Chrome's extension system could allow a malicious extension to execute unauthorized code. While the code execution is restricted within a security 'sandbox,' it represents a significant breakdown of the browser's internal security boundaries. Users are protected by updating to the latest version of the Chrome browser.
Technical details
A use-after-free (UAF) vulnerability exists in the Extensions subsystem of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for extension-related objects, allowing a crafted Chrome Extension to reference memory after it has been freed. An attacker can leverage this to achieve arbitrary code execution (ACE) within the Chrome sandbox. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date