Executive brief
A vulnerability in Google Chrome's internal 'WTF' library could allow a remote attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website, potentially leading to unauthorized access to data or system compromise within the browser's security sandbox. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An integer overflow vulnerability exists in the Web Template Framework (WTF) library within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to execute arbitrary code within the context of the browser's sandbox. The issue was addressed in Chrome version 148.0.7778.216 and later. While the sandbox limits direct access to the underlying operating system, this vulnerability represents a significant step in a multi-stage exploit chain.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in version 148.0.7778.216/217
- 2026-05-28: disclosed: CVE published