Executive brief
A vulnerability exists in Google Chrome's WebNN component on Windows. This component is used to enable machine learning capabilities directly within the web browser. If an attacker has already compromised the browser's rendering process, they could use a specially crafted webpage to cause memory corruption, potentially leading to further control over the affected system.
Technical details
A heap buffer overflow vulnerability was identified in the Web Neural Network (WebNN) API implementation in Google Chrome for Windows. The flaw is rooted in improper input validation (CWE-20) within the WebNN component. To exploit this, a remote attacker must first achieve code execution within the sandboxed renderer process. From that position, the attacker can trigger the overflow by enticing a user to visit a malicious HTML page, leading to heap corruption. This could potentially be used to escape the renderer sandbox or achieve further memory corruption. The issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched