Executive brief
A security vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. By tricking a user into visiting a specially crafted website, a remote attacker could execute unauthorized code on the user's computer. While the exploit is contained within the browser's security sandbox, it could lead to service instability or be used as part of a larger attack chain to compromise the system.
Technical details
A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to achieve arbitrary code execution (ACE) within the context of the Chromium sandbox. The vulnerability was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-03-29: disclosed: Reported by Google internal team
- 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
- 2026-06-04: advisory: NVD publication date