Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebGL component, which handles 3D graphics, could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private data from other open tabs or browser processes.
Technical details
An information disclosure vulnerability exists in the WebGL implementation of Google Chrome prior to version 151.0.7922.72. The flaw stems from an 'inappropriate implementation' that fails to properly isolate or sanitize memory access during graphics rendering. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read sensitive data from the browser's process memory. Google has addressed this issue in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date