Executive brief
A vulnerability exists in Google Chrome's graphics engine, Skia, which could allow a malicious website to access sensitive information from the browser's memory. By tricking a user into visiting a specially crafted webpage, an attacker could potentially observe data they are not authorized to see. This issue primarily impacts the privacy and confidentiality of user data within the browser session.
Technical details
A side-channel information leakage vulnerability (CWE-1300) exists in the Skia graphics library component of Google Chrome. The flaw allows a remote attacker to bypass memory isolation boundaries and extract potentially sensitive information from the browser's process memory. Exploitation requires the victim to load a maliciously crafted HTML page, which leverages side-channel techniques to observe memory states. Google has addressed this issue in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date