Executive brief
A vulnerability in Google Chrome's graphics engine, Skia, could allow a malicious website to access sensitive information from the browser's memory. By tricking a user into visiting a specially crafted webpage, an attacker could potentially steal data from other open tabs or browser processes. This poses a risk to user privacy and the confidentiality of session data.
Technical details
An information disclosure vulnerability exists in the Skia graphics library component of Google Chrome. The flaw is characterized as an 'inappropriate implementation' that allows for out-of-bounds memory access or similar memory safety issues when processing graphics content. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page; when a victim visits the page, the attacker can read sensitive data from the browser's process memory. This vulnerability was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: CVE published