Executive brief
A security vulnerability in Google Chrome on Android could allow a remote attacker to access sensitive information from the device's memory. By tricking a user into visiting a specially crafted website, an attacker could potentially steal private data or disrupt the browser's operations. This issue affects users on Android devices running versions of Chrome older than 148.0.7778.216.
Technical details
An information disclosure vulnerability exists in the GPU component of Google Chrome for Android due to an 'inappropriate implementation.' A remote, unauthenticated attacker can exploit this by inducing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to read sensitive information from the browser's process memory, which could lead to further compromise or data theft. The vulnerability is addressed in Google Chrome version 148.0.7778.216 and later. Chromium developers classified this as High severity.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and Android.
- 2026-05-28: disclosed: CVE published to NVD.