Executive brief
Google Chrome contains a flaw in its Dawn graphics component that allows improper validation of user input. An attacker can exploit this vulnerability by crafting a malicious web page that, when visited, breaks out of Chrome's security sandbox and executes arbitrary code on the victim's computer with full system privileges. This could lead to complete system compromise, theft of sensitive data, and installation of malware.
Technical details
The vulnerability is an improper input validation flaw in the Dawn graphics abstraction layer (a WebGPU implementation component) within Google Chrome. The affected versions are prior to 152.0.7977.65. An attacker can craft a malicious HTML page containing specially crafted input that bypasses validation checks in Dawn, leading to arbitrary code execution outside the Chrome sandbox. The attack vector is network-based and requires only that a user visits or is redirected to the malicious webpage; no special user interaction or authentication is required. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65