Executive brief
A security vulnerability exists in Google Chrome's Headless mode, which is often used for automated web browsing and server-side rendering. An attacker who has already partially compromised the browser's rendering process could use this flaw to break out of the security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or sensitive user data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Headless component of Google Chrome prior to version 148.0.7778.216. The vulnerability is reachable via a crafted HTML page. A precondition for this exploit is that the attacker must have already compromised the renderer process. Successful exploitation allows the attacker to bypass sandbox restrictions, potentially leading to further compromise of the host system. Google has addressed this issue in the stable channel update for desktop.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE published to NVD.