Executive brief
A critical security vulnerability has been identified in Google Chrome's graphics engine (Skia) on Windows. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing them to execute unauthorized code or crash the browser. This could lead to the theft of sensitive information or a complete compromise of the user's browsing session.
Technical details
An integer overflow vulnerability exists in the Skia graphics component of Google Chrome on Windows. The flaw is triggered when processing a specially crafted HTML page, which can lead to an out-of-bounds (OOB) memory write. While the exploit requires the attacker to have already compromised the renderer process (a sandbox escape or secondary stage), it enables further memory corruption that can lead to arbitrary code execution. Google has addressed this in version 148.0.7778.168 for Windows. The vulnerability is tracked as CVE-2026-8510 and was assigned a 'Critical' severity rating by Chromium developers.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-04-14: disclosed: Reported by external researcher q@calif.io
- 2026-05-12: patched: Fixed in Chrome Stable channel update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date