Junglewise Threat Intelligence

CVE-2026-17966: Google Chrome Views information disclosure on macOS

CVE-2026-17966 · Severity: info · CVSS 3.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for macOS contains a security vulnerability in its user interface component. A local attacker could use a specially crafted web page to trick the browser into revealing sensitive information from its internal memory. This could potentially expose private data belonging to the user or other open browser processes.

Technical details

An information disclosure vulnerability exists in the 'Views' component of Google Chrome for macOS. The flaw stems from an inappropriate implementation that fails to properly isolate or protect process memory when rendering specific UI elements. A local attacker can exploit this by enticing a user to visit a specially crafted HTML page, which triggers the memory leak. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. The issue is resolved in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats