Executive brief
A vulnerability was identified in Google Chrome's Skia graphics engine, which is responsible for rendering 2D graphics and text. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive information or a compromise of the user's computer. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An integer overflow vulnerability exists in the Skia graphics library component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to heap-based buffer overflow or heap corruption (CWE-122). A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could allow the attacker to cause a denial-of-service (browser crash) or potentially achieve arbitrary code execution within the context of the browser's renderer process. The issue is resolved in Google Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11124 published.