Executive brief
Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is contained within the browser's security sandbox, it could lead to browser crashes or be used as part of a larger attack to compromise the system.
Technical details
A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of specifically crafted JavaScript or HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage, potentially leading to arbitrary code execution (ACE) within the context of the Chromium sandbox. Google has addressed this issue in version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date