Executive brief
A vulnerability in Google Chrome's WebML component could allow a remote attacker to compromise a user's computer. By tricking a user into visiting a specially crafted website, an attacker could cause the browser to crash or potentially execute unauthorized code. This could lead to the theft of sensitive information or the installation of malicious software.
Technical details
A heap buffer overflow vulnerability (CWE-122) exists in the WebML component of Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could result in arbitrary code execution within the context of the browser's process or a denial-of-service condition. The vulnerability is addressed in Google Chrome version 148.0.7778.168 for Windows.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-13: disclosed: Reported by Syn4pse
- 2026-05-12: patched: Fixed in version 148.0.7778.168
- 2026-05-14: advisory: NVD publication date