Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics processing component could allow a malicious website to bypass the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or full system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome prior to version 147.0.7727.138. The flaw is triggered when the browser improperly manages memory during graphics processing tasks. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation can lead to a sandbox escape, allowing the attacker to execute arbitrary code outside the restricted browser environment on the host operating system. Google has released version 147.0.7727.138 to address this issue.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-03-19: other: Reported to vendor
- 2026-04-28: patched: Fixed in version 147.0.7727.138
- 2026-04-28: advisory: NVD publication date