Executive brief
A vulnerability in Google Chrome on macOS could allow a local attacker to access sensitive information. By using a specially crafted webpage, an attacker could potentially read data from the browser's memory. This could lead to the exposure of private user data or internal browser information.
Technical details
An information disclosure vulnerability exists in the 'Views' component of Google Chrome for macOS. The flaw stems from an inappropriate implementation that fails to properly isolate or protect process memory. A local attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to read sensitive information from the browser's process memory. The issue is fixed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory