Impact
An inappropriate implementation in the password handling component of Google Chrome, prior to version 151.0.7922.72, permits a remote attacker to execute arbitrary code within Chrome’s sandbox when a user loads a specially crafted HTML page. The vulnerability is classified as a privilege escalation weakness (CWE‑269), so the attacker can potentially elevate their capabilities beyond the sandbox. The CVSS score of 8.8 indicates a high severity further highlighting the potential damage.
Affected Systems
The affected product is Google Chrome for desktop. All installations of Chrome running any version earlier than 151.0.7922.72 are vulnerable. This includes users on Windows, macOS and Linux who have not yet received the security update published in July 2026.
Risk and Exploitability
The EPSS score of less than 1 % suggests that exploitation is currently low probability, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the remote code execution capability and the low-level privilege escalation present a serious risk if a malicious website can be reached by an unsuspecting user. Based on the description, the likely attack vector is a web page that the user visits, which contains malicious HTML crafted to trigger the bug. If exploitation succeeds, the attacker can run code with the privileges of the user within the browser sandbox, potentially leading to data theft or further system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA