Executive brief
A vulnerability exists in Google Chrome's font processing component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially leading to memory corruption or an application crash. This could impact the stability of the browser and, in some scenarios, allow for unauthorized actions on the user's device.
Technical details
An integer overflow vulnerability exists in the Fonts component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser processes a specially crafted HTML page containing malicious font data. This leads to an out-of-bounds (OOB) memory write. A remote, unauthenticated attacker can exploit this by hosting a malicious website and enticing a user to visit it. Successful exploitation could result in memory corruption, potentially leading to a sandbox escape or remote code execution when combined with other vulnerabilities. The issue is addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Google Chrome release announcement published.
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.