Executive brief
Google Chrome is a widely used web browser. A vulnerability in its file system component on Mac computers could allow a malicious website to read sensitive information from the browser's memory. To succeed, an attacker would need to trick a user into visiting a specifically crafted webpage and performing certain mouse or keyboard actions.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the FileSystem component of Google Chrome on macOS. The flaw is triggered when a user is enticed to visit a malicious HTML page and perform specific UI gestures. This interaction allows a remote attacker to bypass memory safety boundaries and read potentially sensitive information from the browser's process memory. The issue was addressed in version 148.0.7778.168 for Mac. While the Chromium project internally rated this as 'High' severity, external metrics list it as 'Medium'.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-28: other: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in Chrome version 148.0.7778.168
- 2026-05-14: disclosed: Public advisory published