Executive brief
A security vulnerability in Google Chrome's graphics processing component could allow a malicious website to bypass the browser's security sandbox. If an attacker has already partially compromised the browser's graphics process, they could use this flaw to gain broader access to the underlying computer system. This could lead to unauthorized data access or the execution of malicious software outside of the browser's restricted environment.
Technical details
This vulnerability is classified as an out-of-bounds write (CWE-787) within the GPU process of Google Chrome. The flaw can be triggered by a remote attacker via a specially crafted HTML page, provided the attacker has already achieved a compromise of the GPU process. Successful exploitation allows the attacker to escape the Chrome sandbox and execute code with the privileges of the user running the browser. The vulnerability was addressed in version 147.0.7727.101 for Linux and 147.0.7727.101/102 for Windows and Mac.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-04-02: disclosed: Reported by Google internal researchers
- 2026-04-15: patched: Fixed in Chrome Stable channel update 147.0.7727.101
- 2026-04-15: advisory