Junglewise Threat Intelligence

CVE-2026-10897: Google Chrome out of bounds write in GPU

CVE-2026-10897 · Severity: info · CVSS 10 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability was identified in the Google Chrome web browser's graphics processing component. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to the theft of sensitive data or the installation of malicious software.

Technical details

A critical out-of-bounds write vulnerability (CWE-787) exists in the GPU component of Google Chrome. The flaw stems from an inappropriate implementation that can be triggered when the browser processes a specially crafted HTML page. A remote, unauthenticated attacker can exploit this vulnerability to achieve a sandbox escape, allowing for arbitrary code execution outside of the browser's restricted environment. The vulnerability was addressed in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-05-15: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome stable channel update 149.0.7827.53
  • 2026-06-04: advisory

References

Related threats