Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its graphics engine, Skia, could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it still poses a significant risk to data privacy and system integrity.
Technical details
An integer overflow vulnerability (CWE-190) exists in the Skia graphics library component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to achieve arbitrary code execution within the renderer process sandbox. The vulnerability was addressed in Chrome version 147.0.7727.55. Exploitation requires user interaction (visiting a malicious site) but does not require special privileges.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-23: disclosed: Reported by Google internal researchers
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable release
- 2026-04-08: advisory: NVD publication date