Executive brief
A vulnerability in Google Chrome's USB interface could allow a malicious website to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted webpage, potentially leading to a full system compromise or theft of sensitive data. Users should update their browser to the latest version to mitigate this risk.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebUSB implementation of Google Chrome prior to version 148.0.7778.216. The flaw stems from insufficient validation of untrusted input processed by the USB component. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, leading to arbitrary code execution within the context of the browser process. The vulnerability is rated as Medium severity by Chromium. A fix is available in version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE published to the NVD.