Executive brief
A vulnerability in Google Chrome's graphics processing component could allow a remote attacker to compromise a user's system. By tricking a user into visiting a specially crafted website, an attacker could potentially cause the browser to crash or execute unauthorized actions. This poses a risk to the confidentiality and integrity of user data and the stability of the application.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption in the heap. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website. Successful exploitation could result in information disclosure, application instability, or potentially arbitrary code execution within the context of the browser's renderer or GPU process. The issue is resolved in Google Chrome version 148.0.7778.179 and later.
Affected products
- Google Chrome Prior to 148.0.7778.179
Timeline
- 2026-02-26: other: Reported by David Korczynski (Adalogics)
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: advisory: NVD publication date