Executive brief
Google Chrome for Windows is affected by a security vulnerability in its DataTransfer component, which handles drag-and-drop and copy-paste operations. A local attacker could use a specially crafted web page to access sensitive information stored in the browser's memory. This could lead to the exposure of private data from other open tabs or browser processes.
Technical details
A use-after-free (UAF) vulnerability exists in the DataTransfer component of Google Chrome on Windows. The flaw is triggered when the browser incorrectly manages memory during data transfer operations (such as drag-and-drop), allowing a local attacker to read sensitive information from process memory via a specifically crafted HTML page. This is classified as CWE-416. The vulnerability was addressed in version 151.0.7922.72. While the attack vector is described as local, it typically involves a user visiting a malicious site that interacts with the local browser process.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date