Executive brief
A critical security vulnerability has been identified in Google Chrome's graphics processing component. An attacker who has already gained limited control over a browser tab could use this flaw to break out of the browser's security sandbox. This could allow them to gain full control over the underlying computer system, potentially leading to data theft or the installation of malicious software.
Technical details
A stack-based buffer overflow (CWE-121) exists in the GPU component of Google Chrome. The vulnerability is reachable by a remote attacker who has already compromised the renderer process (e.g., via a separate exploit). By enticing a user to visit a specially crafted HTML page, the attacker can leverage this overflow to achieve a sandbox escape, potentially leading to arbitrary code execution on the host operating system. This issue was fixed in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-05-17: disclosed: Reported by Google internal researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date