Executive brief
A vulnerability exists in Google Chrome's Dawn component, which is responsible for handling modern web graphics. A remote attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could read sensitive information from the browser's memory, potentially leading to further exploitation or data exposure.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, allowing a remote attacker to perform memory reads outside of intended buffers. This is a client-side vulnerability reachable over the network without prior authentication, though it requires user interaction (visiting a site). The issue was addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date