Executive brief
A security vulnerability exists in Google Chrome's Dawn component, which handles web graphics. An attacker who has already partially compromised the browser could use this flaw to break out of the browser's security sandbox. If successful, this would allow the attacker to gain deeper access to the underlying operating system and user data.
Technical details
A use-after-free vulnerability exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process (a 'chained' exploit). By exploiting this memory corruption issue, an attacker can achieve a sandbox escape, leading to arbitrary code execution with the privileges of the browser process. The vulnerability is addressed in Chrome version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-31: other: Reported to Google
- 2026-04-15: disclosed: Initial disclosure date
- 2026-04-15: patched: Fixed in version 147.0.7727.101/102