PT-2026-29459 · Google+1 · Google Chrome+1
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.178
Chromium-based browsers (affected versions not specified)
Description
A use-after-free issue exists in Dawn, the WebGPU layer of Chromium. This flaw can be triggered by a remote attacker using a specially crafted HTML page. If the attacker has already compromised the renderer process, they can achieve arbitrary code execution. This issue has been observed in real-world attacks and is often used as part of multi-stage exploit chains to escape the browser sandbox and compromise the host system.
Recommendations
Update to version 146.0.7680.178 or later.
Apply vendor-specific updates for other Chromium-based browsers.
As a temporary workaround, consider disabling WebGPU or hardware acceleration and restrict access to untrusted web content.
Exploit
Fix
LPE
DoS
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Red Os