Junglewise Threat Intelligence

CVE-2026-10927: Google Chrome out of bounds read in Dawn

CVE-2026-10927 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dawn component could allow a remote attacker to bypass security protections. If an attacker has already compromised the browser's rendering process, they could use this flaw to escape the 'sandbox'—the security layer designed to prevent malicious websites from accessing the rest of the computer. This could lead to unauthorized access to the user's files or operating system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Dawn, the WebGPU implementation in Chromium. The flaw is reachable via a crafted HTML page. A precondition for exploitation is that the attacker must have already compromised the renderer process. By exploiting this memory corruption issue, the attacker can potentially achieve a sandbox escape, allowing for code execution outside of the restricted browser environment. The issue was addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-06: other: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 release
  • 2026-06-04: disclosed: CVE record published

References

Related threats