Executive brief
A vulnerability exists in Google Chrome's Sync feature, which synchronizes user data like bookmarks and history across devices. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code on the user's computer, although this activity would be restricted by the browser's security sandbox.
Technical details
A use-after-free vulnerability (CWE-416) exists in the Sync component of Google Chrome. The flaw is triggered when the browser improperly manages memory during synchronization operations. A remote attacker can exploit this by hosting a malicious HTML page that, when rendered by a vulnerable version of Chrome, triggers the memory corruption. Successful exploitation allows for arbitrary code execution within the context of the Chrome sandbox. The vulnerability is addressed in version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date