Junglewise Threat Intelligence

CVE-2026-10921: Google Chrome integer overflow in Dawn

CVE-2026-10921 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a remote attacker to escape the browser's security sandbox. This occurs if an attacker first compromises the browser's rendering process and then lures a user to a specially crafted website. A successful exploit could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.

Technical details

An integer overflow vulnerability exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when processing a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this overflow to bypass sandbox restrictions and execute arbitrary code on the host operating system. This vulnerability is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) by the vendor. The issue is resolved in Google Chrome version 149.0.7827.53 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-03: disclosed: Reported to Google internally
  • 2026-06-02: patched: Initial stable channel release of fix
  • 2026-06-04: advisory: NVD publication date

References

Related threats