Executive brief
A security vulnerability exists in Google Chrome's Dawn component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data, potentially leading to a full system compromise.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome. Dawn is the implementation of the WebGPU standard in Chromium. The flaw allows a remote attacker to bypass sandbox restrictions by providing malicious input through a specially crafted HTML page. If successfully exploited, this could lead to a sandbox escape, allowing code execution outside of the browser's restricted environment. The vulnerability is addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome stable channel update 149.0.7827.53 released
- 2026-06-04: disclosed: CVE published