Executive brief
Google Chrome is a widely used web browser. A vulnerability in the way the browser handles fonts could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or further exploitation of the system.
Technical details
An integer overflow vulnerability exists in the Fonts component of Google Chrome prior to version 148.0.7778.168. The flaw is triggered when the browser processes specially crafted font data embedded within an HTML page. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution within the confines of the Chromium sandbox. The vulnerability is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) in some contexts, though the primary root cause is an integer overflow. Users are advised to update to version 148.0.7778.168 or later to mitigate this risk.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-14: disclosed: CVE published to the NVD.