Executive brief
A security vulnerability exists in Google Chrome's graphics engine, Skia. By tricking a user into visiting a specially crafted website, an attacker could execute malicious code on the user's computer. While this code is restricted by Chrome's security sandbox, it still represents a significant risk to the integrity of the browser session.
Technical details
A type confusion vulnerability (CWE-843) exists in the Skia graphics library component of Google Chrome. The flaw is triggered when the engine incorrectly processes objects of incompatible types, which can be reached by a remote attacker via a specifically crafted HTML page. Successful exploitation allows for arbitrary code execution within the Chromium sandbox. The vulnerability was addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date