Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Dawn component could allow a malicious website to access sensitive information from the browser's memory. This could lead to the exposure of private data while a user is browsing the web.
Technical details
An object lifecycle vulnerability exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an information disclosure scenario where sensitive data can be read from the process memory. This is likely due to improper management of object states or lifetimes within the Dawn library. The attack is reachable over the network but requires user interaction (visiting a malicious site). Google has addressed this in version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-05-12: patched: Stable channel update released for desktop.
- 2026-05-14: disclosed: CVE published.