Executive brief
Google Chrome contains a critical vulnerability in its ANGLE graphics component, which is used to process 3D content. If a user visits a malicious website, an attacker who has already compromised the browser's initial security layer could use this flaw to break out of the browser's 'sandbox' and gain deeper access to the underlying computer system. This could lead to full system compromise or unauthorized access to sensitive local data.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within the renderer process (e.g., via a separate vulnerability) can exploit this memory corruption issue to bypass the Chrome sandbox. This would allow the attacker to execute arbitrary code with the privileges of the user running the browser. The vulnerability is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-05-14: disclosed: Reported to Google internally
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
- 2026-06-04: advisory: NVD publication date