Executive brief
Google Chrome is a widely used web browser. A vulnerability in its 'Dawn' component, which handles graphics processing, could allow a malicious website to bypass security restrictions. If an attacker has already compromised the browser's rendering process, they could use this flaw to escape the security sandbox and potentially gain broader access to the underlying operating system.
Technical details
A use-after-free (UAF) vulnerability exists in Dawn, the WebGPU implementation in Chromium. The flaw is located within the renderer process and can be triggered by a remote attacker using a specially crafted HTML page. While the renderer process is typically sandboxed, this vulnerability provides a mechanism for a sandbox escape, provided the attacker has already achieved code execution within the renderer. This is classified as a High severity issue by the Chromium project. Users should update to Google Chrome version 149.0.7827.53 or later to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-30: disclosed: Reported by whiter@xuanyusec
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 release
- 2026-06-04: advisory: NVD publication date