Executive brief
A critical security vulnerability in Google Chrome on Android could allow a malicious website to break out of the browser's security sandbox. This type of flaw is serious because it allows an attacker to potentially gain control over the device or access sensitive data beyond the browser's normal limits. Users should update their Chrome browser to the latest version to protect against this threat.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the GPU component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to execute code outside of the restricted sandbox environment. This vulnerability was assigned a 'Critical' severity rating by Chromium developers. The issue is resolved in version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-04-21: other: Reported by researcher cinzinga
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: NVD publication date