Executive brief
A vulnerability in Google Chrome's SwiftShader component could allow a remote attacker to read sensitive information from the browser's memory. This occurs when a user visits a specially crafted website. While this specific flaw primarily impacts data privacy rather than allowing full system takeover, it could be used in combination with other attacks to compromise user security.
Technical details
A heap-based buffer overflow exists in the SwiftShader software renderer within Google Chrome on Mac and iOS. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds (OOB) memory read. An attacker can exploit this to disclose sensitive information from the process memory. The issue is tracked as CWE-122 and was resolved in Chrome version 148.0.7778.168. Attackers require no special privileges, though user interaction (visiting a malicious site) is necessary.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2024-03-05: disclosed: Reported by Cassidy Kim
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date