Executive brief
A vulnerability in the Google Chrome browser on Android could allow a malicious website to interfere with the device's graphics processing unit (GPU). By tricking a user into visiting a specially crafted webpage, an attacker could cause the browser to crash or potentially execute unauthorized actions. This issue has been resolved in the latest software update.
Technical details
A heap-based buffer overflow (CWE-122) exists in the GPU component of Google Chrome on Android. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds memory write. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could lead to memory corruption, potentially allowing for arbitrary code execution within the context of the GPU process or causing a denial-of-service (browser crash). The issue is fixed in version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-04-01: other: Reported to Chromium by Google researchers
- 2026-05-12: patched: Stable channel update released
- 2026-05-14: advisory: NVD publication date