Executive brief
Google Chrome's graphics engine, Skia, contains a vulnerability that could allow an attacker to write data to restricted memory areas. This issue occurs when the browser processes a specially crafted print file. If exploited, an attacker who has already gained a foothold in the browser's rendering process could potentially cause the application to crash or execute unauthorized actions.
Technical details
An out-of-bounds (OOB) memory write vulnerability exists in the Skia graphics component of Google Chrome. The flaw is caused by insufficient validation of untrusted input when handling print files. To exploit this, a remote attacker must first compromise the renderer process. Once achieved, they can use a specially crafted print file to trigger the OOB write. This could lead to memory corruption or further escalation of privileges within the sandboxed environment. The issue is addressed in Chrome version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Chrome Stable Channel Update released
- 2026-05-14: disclosed: NVD publication date