Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine, Skia, could allow a remote attacker to bypass the browser's security sandbox. If an attacker has already compromised the initial rendering process, they could use this flaw to gain broader access to the underlying operating system, potentially leading to full system compromise or data theft.
Technical details
An integer overflow vulnerability exists in the Skia graphics component of Google Chrome versions prior to 150.0.7871.47. The flaw can be triggered by a crafted HTML page. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this overflow to escape the Chrome sandbox. This would allow the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. Users are advised to update to version 150.0.7871.47 or later to mitigate this risk.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47