Executive brief
A critical security vulnerability has been identified in Google Chrome's ANGLE component, which handles graphics processing. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially leading to a complete compromise of the browser or the underlying system. This could result in the theft of sensitive user data, unauthorized access to accounts, or the installation of malicious software.
Technical details
A type confusion vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the engine incorrectly processes data types, leading to an out-of-bounds write and subsequent heap corruption. A remote attacker can exploit this by hosting a malicious HTML page; when a victim visits the site, the attacker can achieve arbitrary code execution within the context of the browser's renderer process. This vulnerability is tracked as CWE-787 and was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-17: disclosed: Reported by Maher Azzouzi
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date