Executive brief
A security vulnerability exists in Google Chrome for Mac that could allow a malicious website to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted webpage, an attacker could potentially gain unauthorized access to the underlying operating system. This poses a significant risk to data confidentiality and system integrity for users of the affected browser versions.
Technical details
A heap buffer overflow vulnerability (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on macOS. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to achieve a sandbox escape, potentially executing arbitrary code with the privileges of the user. The vulnerability was addressed in Chrome version 148.0.7778.168 for Mac.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-30: disclosed: Reported by Nathaniel Oh (@calysteon)
- 2026-05-12: patched: Fixed in version 148.0.7778.168
- 2026-05-14: advisory: NVD publication date