Executive brief
A vulnerability in Google Chrome's graphics processing component could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already compromised the browser's rendering process could escape the 'sandbox'—a security layer designed to keep web threats from affecting the rest of the computer. This could lead to unauthorized access to the user's system or data.
Technical details
A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during graphics processing, allowing an attacker to reference memory after it has been freed. To exploit this, a remote attacker must first compromise the renderer process (e.g., via a separate vulnerability) and then use a crafted HTML page to trigger the UAF in the GPU process. Successful exploitation can lead to a sandbox escape, allowing the attacker to execute code outside of the restricted browser environment. This issue was resolved in Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-03-18: disclosed: Reported to Chromium project
- 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
- 2026-06-30: advisory: NVD publication date