Executive brief
A vulnerability in Google Chrome's Dawn component could allow a remote attacker to execute unauthorized code on a user's computer. This occurs when a user visits a specially crafted website. While the attack is limited to the browser's security sandbox, it could be used as a starting point for further attacks on the system.
Technical details
A 'bad cast' vulnerability exists in Dawn, the WebGPU implementation in Chromium. The flaw is triggered when the application incorrectly casts a pointer or object to an incompatible type, leading to memory corruption. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, potentially leading to arbitrary code execution within the renderer process sandbox. The vulnerability is tracked as CWE-125 (Out-of-bounds Read) in some contexts, though the primary description notes a bad cast. Users should update to Google Chrome version 149.0.7827.53 or later to mitigate this risk.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome stable channel update released
- 2026-06-04: disclosed: CVE published to NVD