Junglewise Threat Intelligence

CVE-2026-10993: Google Chrome heap buffer overflow in Skia

CVE-2026-10993 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's Skia graphics engine, which is responsible for rendering 2D graphics and text. By tricking a user into visiting a specially crafted website, an attacker could exploit this flaw to access sensitive information stored in the browser's memory. This could lead to the exposure of private data from other open tabs or browser processes.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Skia graphics library within Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, leading to an out-of-bounds memory access. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. The vulnerability was addressed in Google Chrome version 149.0.7827.53. Access to specific bug details remains restricted to prevent widespread exploitation until more users have updated.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome Stable channel update 149.0.7827.53
  • 2026-06-04: disclosed: CVE published by NVD

References

Related threats