Junglewise Threat Intelligence

CVE-2026-10009: Google Chrome integer overflow in Skia

CVE-2026-10009 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to execute unauthorized code on a user's computer. While the attack is limited by the browser's security sandbox, it could be used as part of a larger chain to compromise the system or access sensitive user data. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An integer overflow exists in Skia, the 2D graphics library used by Google Chrome. The vulnerability is reachable via a crafted HTML page. An attacker who has already compromised the renderer process can exploit this flaw to execute arbitrary code inside the Chrome sandbox. This is classified by Chromium as a High severity issue. The vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats