Executive brief
A vulnerability in Google Chrome's graphics engine could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's rendering process could gain unauthorized access to data from other open websites. This undermines 'site isolation,' a core security feature designed to keep data from different websites separate and secure.
Technical details
An uninitialized variable vulnerability (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already achieved a compromise of the renderer process. By exploiting this uninitialized state, a remote attacker can bypass site isolation protections, potentially leading to cross-origin data access. The issue was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: NVD publication date