Executive brief
A vulnerability in Google Chrome's password management component could allow a remote attacker to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted, malicious website. While the exploit is limited to the browser's security sandbox, it represents a potential risk to the integrity of the application and could be used as part of a larger attack chain.
Technical details
An inappropriate implementation vulnerability exists within the Passwords component of Google Chrome. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the confines of the browser's sandbox environment. The vulnerability is addressed in Google Chrome version 151.0.7922.72. Chromium developers have classified this issue with a 'Low' security severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date