Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebSockets component could allow a malicious website to bypass the browser's security sandbox. If successfully exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's normal restrictions.
Technical details
A Use-After-Free (UAF) vulnerability exists in the WebSockets implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during WebSocket communication, which can be induced by a remote attacker through a specially crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing code execution outside of the restricted browser environment. The vulnerability is addressed in Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date