Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine, Skia, could allow a malicious website to execute unauthorized code on a user's computer. While the browser's security sandbox limits the immediate impact, such an exploit could be used as part of a larger attack to compromise user data or system stability.
Technical details
An out-of-bounds memory access vulnerability exists in the Skia graphics component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to achieve arbitrary code execution within the context of the Chromium render process sandbox. This vulnerability is categorized by Chromium as High severity. The issue is resolved in Google Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-18: disclosed: Reported to Chrome by Google researchers
- 2026-06-02: patched: Fixed in Chrome stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date