Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics processing component could allow a remote attacker to access sensitive information from the browser's memory. This requires the attacker to first compromise a website's rendering process and then trick a user into visiting a specially crafted web page.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for Mac and Windows prior to version 148.0.7778.168. The flaw is reachable by a remote attacker who has already compromised the renderer process. By convincing a user to load a specially crafted HTML page, the attacker can exploit this memory safety issue to read sensitive information from the process memory. This vulnerability was reported by Google internally and is addressed in the Stable Channel update 148.0.7778.167/168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-03-29: disclosed: Reported to Chromium project
- 2026-05-12: patched: Fixed in Stable Channel Update for Desktop
- 2026-05-14: advisory: NVD publication date