Executive brief
A vulnerability exists in Google Chrome's WebGL component, which is used to render 3D graphics in the browser. By tricking a user into visiting a specially crafted website, an attacker could potentially access sensitive information stored in the browser's memory. This could lead to the exposure of private data from other open tabs or browser processes.
Technical details
A use-after-free (UAF) vulnerability exists in the WebGL implementation of Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser improperly manages memory lifecycle for WebGL objects, allowing a remote attacker to exploit the 'use-after-free' condition via a specially crafted HTML page. Successful exploitation allows the attacker to perform an out-of-bounds read of the browser's process memory, potentially leading to the disclosure of sensitive information. The vulnerability is addressed in version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Fixed in Chrome Stable channel update 149.0.7827.53
- 2026-06-04: disclosed: CVE published to NVD