Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine could allow a remote attacker to access sensitive information from the browser's memory if a user opens a specially crafted file. This could lead to the exposure of private data or help facilitate further attacks against the user's system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the Skia graphics component of Google Chrome. The flaw is triggered when the browser processes a specially crafted file, leading to memory access outside of the intended buffer. A remote, unauthenticated attacker can exploit this by inducing a user to open a malicious file or visit a compromised website, potentially resulting in the disclosure of sensitive information from the browser's process memory. The issue is addressed in Google Chrome version 147.0.7727.101.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-04-15: disclosed
- 2026-04-15: advisory
- 2026-04-15: patched: Fixed in version 147.0.7727.101