Executive brief
Google Chrome is a widely used web browser. A vulnerability in its Skia graphics engine could allow a remote attacker who has already partially compromised the browser to execute malicious code. This could lead to a full takeover of the browser's sandbox environment, potentially impacting user data and system security.
Technical details
An integer overflow vulnerability exists in the Skia graphics component of Google Chrome. The flaw is reachable via a specially crafted HTML page. An attacker who has already achieved code execution within a compromised renderer process can leverage this overflow to execute arbitrary code inside the browser's sandbox. This vulnerability was addressed in Chrome version 148.0.7778.216. The issue is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) by some sources, though the primary description identifies it as an integer overflow.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Chrome Stable channel updated to 148.0.7778.216/217
- 2026-05-28: disclosed: NVD publication date