Junglewise Threat Intelligence

CVE-2026-10925: Google Chrome out of bounds write in Skia

CVE-2026-10925 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine (Skia) could allow a malicious website to bypass security protections designed to isolate the browser from the rest of the computer. If exploited, this could allow an attacker who has already gained some control over the browser to access sensitive data or execute unauthorized commands on the user's Mac.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the Skia graphics component of Google Chrome on macOS. The flaw is reachable via a crafted HTML page. A remote attacker who has already compromised the renderer process can leverage this memory corruption to potentially perform a sandbox escape, gaining elevated privileges on the host system. The vulnerability was addressed in Chrome version 149.0.7827.53. This issue specifically affects the Mac platform.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-06: other: Reported by Google internally
  • 2026-06-02: patched: Fixed in version 149.0.7827.53/54
  • 2026-06-04: disclosed: NVD publication date

References

Related threats