Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics processing component could allow a malicious website to access sensitive information from the computer's memory. This occurs if an attacker has already partially compromised the browser's page-rendering process, potentially leading to the exposure of private user data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the GPU component of Google Chrome. The flaw allows a remote attacker to perform an information disclosure attack. To exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability) and then entice a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the process memory. The issue is resolved in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: NVD publication date