Executive brief
A security vulnerability in Google Chrome's graphics processing component could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised a website's rendering process, they could use this flaw to gain broader access to the underlying computer system. This could lead to unauthorized data access or the installation of malicious software on the user's device.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the GPU component of Google Chrome prior to version 148.0.7778.216. The flaw is exploitable by a remote attacker who has already compromised the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can leverage this memory corruption to escape the Chrome sandbox and execute arbitrary code with elevated privileges on the host system. Google has addressed this issue in the stable channel update 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date