Executive brief
Google Chrome, a widely used web browser, is affected by a security vulnerability in its media processing components. An attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code within the browser's restricted environment, potentially leading to further attacks or instability.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to achieve arbitrary code execution within the renderer sandbox. While the impact is limited by the sandbox, it represents a significant memory safety issue. The vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date