Executive brief
A vulnerability in the Google Chrome web browser could allow a malicious website to bypass security protections. By tricking a user into visiting a specially crafted webpage, an attacker could escape the browser's 'sandbox,' which is designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the user's system or data.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the GPU component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to write data outside of intended memory buffers. This memory corruption can be leveraged to achieve a sandbox escape, potentially allowing arbitrary code execution on the underlying operating system. The vulnerability was addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD