Executive brief
Google Chrome, a widely used web browser, contains a security vulnerability in its developer tools (DevTools). If a user is tricked into installing a malicious browser extension, an attacker could execute unauthorized code within the browser's restricted security sandbox. While the impact is limited to the sandbox, it represents a breakdown of the browser's internal security boundaries.
Technical details
A use-after-free (UAF) vulnerability exists in the DevTools component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the execution of a specially crafted Chrome Extension. To exploit this, an attacker must first persuade a user to install a malicious extension. Successful exploitation allows for arbitrary code execution within the browser's sandbox environment. The issue is addressed in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-07-30: disclosed: NVD publication date.