Executive brief
A vulnerability exists in Google Chrome's media handling component that could allow an attacker to bypass security protections. If a user visits a specially crafted website, an attacker who has already partially compromised the browser's rendering process could escape the 'sandbox'—a security layer designed to isolate the browser from the rest of the computer. This could lead to unauthorized access to the underlying operating system or user data.
Technical details
A Use-After-Free (UAF) vulnerability exists in the Media component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already achieved code execution within a compromised renderer process. By exploiting this memory corruption issue, the attacker can potentially achieve a sandbox escape, gaining elevated privileges on the host system. The vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed