Junglewise Threat Intelligence

CVE-2026-10919: Google Chrome use after free in ANGLE

CVE-2026-10919 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's graphics layer (ANGLE) that could allow a malicious website to break out of the browser's security sandbox. If an attacker first compromises the process responsible for rendering web content, they could use this flaw to gain unauthorized access to the underlying operating system or user data. This could lead to full system compromise or the theft of sensitive information stored on the device.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during graphics rendering operations. An attacker who has already achieved code execution within the renderer process (e.g., via a separate V8 exploit) can leverage this UAF to bypass the Chrome sandbox. Successful exploitation via a specially crafted HTML page could allow the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. Google has addressed this in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-02: disclosed: Reported to Chrome by Google researchers
  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: advisory: NVD publication date

References

Related threats