Executive brief
A security vulnerability in Google Chrome on macOS could allow a malicious website to access sensitive information from the browser's memory. This occurs due to a flaw in how the browser's graphics processing component handles data. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of private user data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for macOS. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read data beyond the intended buffer in process memory. This is a network-based attack that requires user interaction (visiting a malicious site) but no prior authentication. Successful exploitation can lead to the disclosure of sensitive information from the browser's memory space. The issue was addressed in Chrome version 148.0.7778.179 for Mac.
Affected products
- Google Chrome prior to 148.0.7778.179
Timeline
- 2026-03-04: other: Reported by researcher
- 2026-05-19: patched: Stable channel update released
- 2026-05-20: advisory: NVD publication date