Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability in its WebGL component could allow a malicious website to bypass the browser's security sandbox. If exploited, an attacker who has already gained limited control over a browser tab could escalate their access to the underlying operating system, potentially leading to full system compromise and data theft.
Technical details
A critical vulnerability exists in the WebGL component of Google Chrome due to insufficient validation of untrusted input. The flaw allows a remote attacker who has already compromised the renderer process to perform a sandbox escape. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this input validation failure to execute code outside of the restricted browser environment. This vulnerability was addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-04-17: disclosed: Reported by Google internal researchers
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: advisory: NVD publication date