Executive brief
Google Chrome is a widely used web browser deployed across millions of devices for browsing the internet. A buffer overflow vulnerability in Chrome's network handling component allows a remote attacker to execute arbitrary code outside the browser's security sandbox via a specially crafted webpage. This could lead to complete compromise of the system, including theft of user data and malware installation.
Technical details
A buffer overflow vulnerability exists in the Network component of Google Chrome prior to version 151.0.7922.173. The vulnerability can be triggered remotely by serving a crafted HTML page to a victim, allowing arbitrary code execution outside the browser sandbox. This represents a critical escape from Chrome's sandboxing security model, which normally isolates the rendering engine from the operating system. The attack requires no special user privileges or preconditions beyond visiting a malicious webpage. Google patched this issue in Chrome 151.0.7922.173 released on August 20, 2026.
Affected products
- Google Chrome prior to 151.0.7922.173
Timeline
- 2026-08-20: disclosed
- 2026-08-20: patched: Chrome 151.0.7922.173 released