Executive brief
A security vulnerability exists in Google Chrome's graphics engine (Skia) on macOS. This flaw could allow a malicious website to access sensitive information from other open websites or browser processes if the attacker has already partially compromised the browser's internal rendering system. Users are advised to update to the latest version of Chrome to mitigate this risk.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Skia graphics component of Google Chrome on macOS. The vulnerability is reachable by a remote attacker who has already compromised the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit this memory safety issue to leak sensitive cross-origin data. The issue was addressed in Chrome version 150.0.7871.47 for Mac.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-05-13: disclosed: Reported to Google internally
- 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
- 2026-06-30: advisory