Junglewise Threat Intelligence

CVE-2026-10881: Google Chrome out of bounds read and write in ANGLE

CVE-2026-10881 · Severity: info · CVSS 10 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A critical vulnerability in its graphics engine (ANGLE) could allow a remote attacker to escape the browser's security sandbox by tricking a user into visiting a specially crafted website. If successful, this could allow the attacker to gain full control over the underlying computer system and access sensitive user data.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, leading to memory corruption. This vulnerability is classified as 'Critical' by Chromium because it can be leveraged by a remote, unauthenticated attacker to achieve a sandbox escape, potentially leading to arbitrary code execution on the host operating system. The issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-02: disclosed: Reported by anonymous researcher
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
  • 2026-06-04: advisory: NVD publication date

References

Related threats