Executive brief
Google Chrome is a widely used web browser. A vulnerability in its compositing engine—the component responsible for drawing web page elements—could allow a malicious website to access sensitive data from other websites you have open. This could lead to the exposure of private information, though an attacker would first need to have already compromised a specific part of the browser's internal processes.
Technical details
An object corruption vulnerability exists in the Compositing component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already achieved code execution within a compromised renderer process (a 'sandbox escape' or similar initial compromise is a prerequisite). If successful, the attacker can bypass cross-origin isolation boundaries to leak sensitive data from other origins. Google has addressed this in version 148.0.7778.168. While the provided CVSS score is 3.1 (Low), Chromium's internal severity rating is High due to the potential for cross-origin data exfiltration.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-29: disclosed: Reported to Chromium by Google researchers
- 2026-05-12: patched: Fixed in Chrome Stable channel update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date