Executive brief
A critical security vulnerability has been identified in Google Chrome's Dawn component, which handles web graphics. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.
Technical details
A use-after-free (UAF) vulnerability exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects within the Dawn component during the processing of web content. A remote attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation allows the attacker to escape the Chrome renderer sandbox and execute arbitrary code with the privileges of the user on the host operating system. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-04-08: disclosed: Reported by anonymous researcher
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: advisory: NVD publication date