Executive brief
A security vulnerability has been identified in the Google Chrome web browser's graphics processing component. By tricking a user into visiting a specially crafted website, a remote attacker could potentially execute malicious code on the user's computer. This could lead to unauthorized access to sensitive data, system compromise, or the installation of malware.
Technical details
A heap-based buffer overflow (CWE-122) exists in the GPU component of Google Chrome. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to overflow memory and potentially achieve arbitrary code execution. The attack requires minimal user interaction (visiting a malicious URL) and has a high impact on confidentiality, integrity, and availability. Google has addressed this issue in version 146.0.7680.178 for Windows and Mac, and 146.0.7680.177 for Linux.
Affected products
- Google Chrome prior to 146.0.7680.178
Timeline
- 2026-03-11: other: Reported by researcher inspector-ambitious
- 2026-03-31: patched: Stable channel update released
- 2026-04-01: disclosed: NVD publication date