CVE-2026-10941

Google · Chrome

An out-of-bounds memory access vulnerability in the Skia graphics library of Google Chrome may lead to unauthorized data access or application crashes.

Executive summary

An out-of-bounds memory access flaw in the Google Chrome Skia library creates a high-severity risk of system instability and potential arbitrary code execution.

Vulnerability

This vulnerability is an out-of-bounds memory access issue within the Skia graphics library. An unauthenticated attacker could trigger this flaw by enticing a user to visit a malicious website, leading to memory corruption.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe threat to end-user workstations. Successful exploitation could lead to the exposure of sensitive memory contents or allow attackers to bypass security controls, resulting in unauthorized access to corporate resources.

Remediation

Immediate Action: Upgrade Google Chrome to version 149 or higher to receive the necessary security patches for the Skia library.

Proactive Monitoring: Review endpoint security logs for anomalous graphical rendering errors or unexpected browser process terminations.

Compensating Controls: Utilize endpoint protection platforms (EPP) to block known malicious domains and enforce restricted browsing policies.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The severity of this memory-related vulnerability necessitates immediate patching. Organizations should deploy the update across all environments to prevent potential exploitation and maintain the integrity of browser-based operations.