Executive brief
A security vulnerability exists in the graphics processing component of Google Chrome and ChromeOS. An attacker could use a specially crafted website to break out of the browser's security sandbox, potentially gaining control over the underlying operating system. This could lead to the theft of sensitive data or the installation of malicious software on the user's device.
Technical details
An integer overflow vulnerability exists in the GPU component of Google Chrome and ChromeOS. The flaw is triggered when processing a specially crafted HTML page. An attacker who has already compromised the renderer process can exploit this overflow to achieve a sandbox escape, potentially gaining elevated privileges on the host system. The vulnerability affects Linux and ChromeOS versions prior to 148.0.7778.168. Users are advised to update to the latest stable channel release to mitigate this risk.
Affected products
- Google ChromeOS prior to 148.0.7778.168
- Google Chrome prior to 148.0.7778.168 (Linux)
Timeline
- 2026-03-23: disclosed: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in version 148.0.7778.168
- 2026-05-14: advisory: NVD publication date