Junglewise Threat Intelligence

CVE-2026-10018: Google Chrome integer overflow in ANGLE

CVE-2026-10018 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This occurs when the browser processes a specially crafted web page, potentially leading to the exposure of private data from other open tabs or browser processes. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an improper memory operation. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This issue was addressed in Chrome version 148.0.7778.216 and later. The vulnerability is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) by some sources, though the primary root cause is an integer overflow.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: NVD publication date.

References

Related threats