Executive brief
A security vulnerability exists in Google Chrome's Tint component, which is responsible for handling web graphics shaders. By tricking a user into visiting a specially crafted website, an attacker could bypass the browser's security sandbox. This could allow the attacker to execute unauthorized code on the underlying operating system, potentially leading to full system compromise or data theft.
Technical details
A type confusion vulnerability (CWE-843) exists in Tint, the compiler for the WebGPU Shading Language (WGSL) in Google Chrome. The flaw occurs when the engine processes incompatible types, which can be triggered by a remote attacker via a malicious HTML page containing crafted shader code. Successful exploitation allows the attacker to break out of the Chromium renderer sandbox and execute arbitrary code in the context of the operating system. The vulnerability was addressed in Google Chrome version 150.0.7871.46.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Fixed in Chrome 150.0.7871.46 stable channel update.
- 2026-07-01: disclosed: CVE published to NVD.