Executive brief
A vulnerability in Google Chrome's WebML component could allow a remote attacker to interfere with the browser's memory. By tricking a user into visiting a specially crafted website, an attacker could potentially cause the browser to crash or execute unauthorized actions. This affects users on Windows, Mac, and Linux systems using older versions of the Chrome browser.
Technical details
An out-of-bounds (OOB) memory write vulnerability exists in the WebML component of Google Chrome due to insufficient validation of untrusted input. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to perform an out-of-bounds write, which can lead to memory corruption, application instability, or potentially arbitrary code execution within the browser's sandbox. The issue is addressed in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-20: disclosed: Reported to Chromium by ningxin.hu@intel.com
- 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
- 2026-04-08: advisory