Executive brief
Google Chrome, a widely used web browser, contained a security vulnerability in its Skia graphics engine. An attacker who has already partially compromised the browser's rendering process could exploit this flaw to read sensitive information from the computer's memory. This could lead to the exposure of private data or help an attacker bypass other security protections.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Skia graphics component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform an out-of-bounds memory read via a specially crafted HTML page. This enables the attacker to leak sensitive information from the process memory, potentially facilitating further exploitation or data theft. The issue is addressed in Google Chrome version 150.0.7871.46 and later.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Stable channel update released for desktop.
- 2026-07-01: disclosed: NVD publication date.