Executive brief
Google Chrome is a widely used web browser. A critical vulnerability was found in its Skia graphics engine that could allow a malicious website to bypass the browser's security sandbox. If exploited, an attacker who has already gained a foothold in the browser's rendering process could potentially take full control of the underlying operating system, leading to data theft or malware installation.
Technical details
A critical input validation vulnerability exists in the Skia graphics library component of Google Chrome. The flaw is triggered by insufficient validation of untrusted input when processing graphics data. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this vulnerability via a specially crafted HTML page to escape the sandbox and execute arbitrary code on the host system. This vulnerability was addressed in Chrome version 150.0.7871.47 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-25: disclosed: Reported to Chromium project
- 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
- 2026-06-30: advisory: NVD publication date