Executive brief
A vulnerability in Google Chrome's graphics processing component on macOS could allow a malicious website to read sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for macOS. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform unauthorized memory reads. This is a client-side vulnerability requiring user interaction (visiting a malicious site). While the CVSS score is 4.3 (Medium), Chromium developers have assigned it a 'High' severity rating. The issue is resolved in version 148.0.7778.179 for Mac.
Affected products
- Google Chrome Prior to 148.0.7778.179
Timeline
- 2026-03-04: other: Reported by researcher
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: advisory: NVD publication date