Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its Dawn component, which handles graphics processing. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to break out of the browser's security sandbox. If successful, this could lead to unauthorized access to the underlying operating system and the user's private data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome. Dawn is the implementation of the WebGPU standard, and the flaw stems from insufficient validation of untrusted input processed by this component. A remote attacker can exploit this vulnerability by enticing a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation could allow the attacker to achieve a sandbox escape, potentially leading to arbitrary code execution on the host system. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date