Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its Dawn component (the engine responsible for WebGPU graphics) could allow a malicious website to break out of the browser's security sandbox. If successful, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying Linux or ChromeOS system, potentially leading to unauthorized data access or full system compromise.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome for Linux and ChromeOS. Dawn is the implementation of the WebGPU standard in Chromium. The vulnerability is reachable by a remote attacker who can entice a user to visit a specially crafted HTML page. A successful exploit requires the attacker to have already achieved code execution within the sandboxed renderer process; from there, the insufficient validation in Dawn allows for a sandbox escape to the browser process or host operating system. Google has addressed this in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
- Google ChromeOS prior to 149.0.7827.103
Timeline
- 2026-05-27: disclosed: Reported to Chrome by Google researchers
- 2026-06-08: patched: Fixed in Stable Channel Update 149.0.7827.102/.103
- 2026-06-09: advisory: NVD publication date