Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its font processing component. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's computer. While the attack is limited by the browser's security sandbox, it could lead to unauthorized data access or serve as a stepping stone for further system compromise.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the Fonts component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page containing malicious font data. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution within the context of the browser's sandboxed process. This vulnerability was addressed in Google Chrome version 148.0.7778.168 for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-04-16: disclosed: Reported by Matej Smycka
- 2026-05-12: patched: Fixed in Chrome Stable Channel Update 148.0.7778.167/168
- 2026-05-14: advisory: NVD publication date