Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Dawn component, which handles graphics processing, could allow a malicious website to bypass the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data.
Technical details
An object lifecycle vulnerability exists in Dawn, the WebGPU implementation in Chromium. The flaw is triggered when the browser processes a specially crafted HTML page, leading to improper management of object states. A remote, unauthenticated attacker can exploit this to achieve a sandbox escape, potentially gaining execution privileges outside of the restricted browser process. The issue was addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published