Executive brief
A vulnerability in Google Chrome's Tracing component on Windows could allow a local attacker to gain elevated system privileges. By tricking a user into opening a specially crafted malicious file, an attacker could bypass security boundaries to execute commands with higher authority than the current user. This could lead to full control over the affected workstation and potential access to sensitive local data.
Technical details
A use-after-free (UAF) vulnerability exists in the Tracing component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of tracing data, specifically when handling a malicious file provided by a local attacker. An attacker can exploit this memory corruption to execute arbitrary code and escalate privileges to the operating system level. The vulnerability is assigned CWE-416 and was addressed in Chrome version 151.0.7922.72. Exploitation requires local access and user interaction to open the malicious file.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72 for Windows
- 2026-07-30: disclosed: NVD publication date