Executive brief
A security vulnerability in Google Chrome for macOS could allow a malicious website to bypass the browser's security sandbox. This occurs when the browser handles gamepad input, potentially allowing an attacker who has already gained limited control over a browser tab to take full control of the user's computer. Users should update to the latest version of Chrome to protect their data and system integrity.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the Gamepad component of Google Chrome for macOS. The flaw allows a remote attacker who has already compromised the renderer process (e.g., via a separate exploit) to escape the Chrome sandbox by providing a specially crafted HTML page. This sandbox escape could lead to arbitrary code execution with the privileges of the browser process. The issue is resolved in Chrome version 148.0.7778.216 for Mac.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date