Description
Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use‑after‑free in the Views component of Google Chrome for macOS can cause heap corruption when a specially crafted HTML page is displayed. If the attacker succeeds, arbitrary code could be executed or the browser could crash. The weakness is tied to memory management flaws identified as CWE‑416 and CWE‑787.

Affected Systems

All users running Google Chrome on macOS with a version older than 151.0.7922.72 are affected. The vulnerability has been documented for Chrome prior to this stable‐channel update.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is considered high impact. The EPSS score of less than 1% indicates a very low yet non‑zero likelihood of exploitation in the near term, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would most likely occur remotely by delivering a crafted webpage that triggers the use‑after‑free. No confirmed exploits are publicly known at this time.

Generated by OpenCVE AI on August 3, 2026 at 12:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 151.0.7922.72 or newer to eliminate the vulnerability.
  • Use managed policies to enforce the update and prevent rollback to older, vulnerable versions.
  • Apply restrictive content‑security policies or enable hardware sandboxing to reduce the risk from remaining memory‑corruption weaknesses.

Generated by OpenCVE AI on August 3, 2026 at 12:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in Views
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 30 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T03:56:12.341Z

Reserved: 2026-07-27T23:34:37.754Z

Link: CVE-2026-17752

cve-icon Vulnrichment

Updated: 2026-07-30T16:16:38.181Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:38.130

Modified: 2026-08-03T17:57:01.153

Link: CVE-2026-17752

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:11Z

Links: CVE-2026-17752 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:30:17Z

Weaknesses