Executive brief
Google Chrome is a widely used web browser. A vulnerability in its user interface component on Linux could allow a malicious website to break out of the browser's security sandbox. If successful, this could allow an attacker to gain unauthorized access to the underlying operating system and the user's private files.
Technical details
An integer overflow vulnerability exists in the User Interface (UI) component of Google Chrome on Linux. The flaw is rooted in improper input validation (CWE-20) when processing content from a crafted HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could lead to a sandbox escape, allowing the attacker to execute code outside of the restricted browser environment. This issue was addressed in Chrome version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-05-16: disclosed: Reported to Chrome by Google internal researchers
- 2026-06-08: patched: Fixed in stable channel update 149.0.7827.103
- 2026-06-09: advisory: NVD publication date