Executive brief
Google Chrome is a widely used web browser. A critical vulnerability in its graphics engine (ANGLE) could allow a remote attacker to escape the browser's security sandbox by tricking a user into visiting a specially crafted website. If successful, this could allow the attacker to gain full control over the underlying computer system and access sensitive user data.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, leading to memory corruption. This vulnerability is classified as 'Critical' by Chromium because it can be leveraged by a remote, unauthenticated attacker to achieve a sandbox escape, potentially leading to arbitrary code execution on the host operating system. The issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-02: disclosed: Reported by anonymous researcher
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
- 2026-06-04: advisory: NVD publication date