Executive brief
A vulnerability in Google Chrome for macOS could allow a malicious website to access sensitive information from the browser's memory. This occurs due to a flaw in how the browser handles Input Method Editors (IME), which are used for entering text in different languages. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of private data.
Technical details
An information disclosure vulnerability exists in the Input Method Editor (IME) component of Google Chrome for macOS. The flaw stems from an inappropriate implementation that fails to properly isolate or protect process memory during certain IME operations. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the browser's process memory. This issue is fixed in Google Chrome version 151.0.7922.72 for Mac.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date