Executive brief
Google Chrome contains a memory corruption vulnerability in the Tint component on macOS that allows a remote attacker to execute arbitrary code outside the browser sandbox by serving a crafted HTML page. This could give attackers full access to the user's system, potentially leading to data theft, malware installation, and complete system compromise.
Technical details
The vulnerability is a memory corruption flaw in Chrome's Tint component that can be exploited remotely via a crafted HTML page. The vulnerability allows an attacker to potentially execute arbitrary code outside the sandbox protection mechanism. The attack vector is network-based and requires user interaction (visiting a malicious website). Google has assigned this a High security severity rating and it affects Chrome versions prior to 152.0.7977.65 on macOS. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed: Chrome 152.0.7977.65 released with patch
- 2026-05-01: other: Vulnerability reported by andryskowski.michal