Junglewise Threat Intelligence

CVE-2026-9998: Google Chrome integer overflow in Skia

CVE-2026-9998 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's graphics engine, Skia. An attacker who has already gained partial control over a browser process could use this flaw to break out of the browser's security sandbox. This could allow them to gain broader access to the underlying operating system and user data.

Technical details

An integer overflow vulnerability exists in the Skia graphics library component of Google Chrome. The flaw is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this overflow to bypass sandbox restrictions (sandbox escape). This would allow the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. The issue is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats