Executive brief
A critical security vulnerability has been identified in Google Chrome for Android that could allow a malicious website to break out of the browser's security sandbox. By tricking a user into visiting a specially crafted webpage, an attacker could gain unauthorized access to the underlying operating system. This could lead to the theft of sensitive personal data or the installation of malicious software on the device.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in Dawn, the WebGPU implementation in Google Chrome. The flaw is triggered when processing a maliciously crafted HTML page, allowing a remote attacker to bypass the browser's sandbox boundaries. This vulnerability is classified as Critical by Chromium developers because it enables an attacker who has already compromised a renderer process to escalate privileges to the browser process or the underlying Android OS. The issue is resolved in Google Chrome for Android version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and mobile versions.
- 2026-05-28: disclosed: NVD publication date.