Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its Frame component. This flaw could allow a malicious website to access memory outside of its intended boundaries when a user visits a specially crafted page. While rated as low severity, such issues can potentially lead to browser instability or be used in combination with other flaws to compromise user data.
Technical details
An inappropriate implementation vulnerability exists in the Frame component of Google Chrome. The flaw allows for out-of-bounds memory access when processing a maliciously crafted HTML page. A remote attacker could exploit this by enticing a user to visit a specific URL, potentially leading to information disclosure or process instability. The vulnerability is addressed in version 151.0.7922.72 and later. The Chromium project has classified this as a Low severity issue.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date