Executive brief
A critical security vulnerability has been identified in the Google Chrome web browser's WebGL component, which handles 3D graphics. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in the WebGL implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the rendering of 3D graphics content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage containing crafted HTML and WebGL instructions. Successful exploitation can lead to a sandbox escape, allowing the attacker to execute arbitrary code outside of the browser's restricted environment. This issue was addressed in Chrome version 149.0.7827.196/197.
Affected products
- Google Chrome Prior to 149.0.7827.196/197
Timeline
- 2026-06-07: disclosed: Reported by anonymous researcher
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: NVD publication date