Junglewise Threat Intelligence

CVE-2026-10930: Google Chrome out of bounds read in ANGLE on Mac

CVE-2026-10930 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Mac could allow a remote attacker to read sensitive information from the computer's memory. This occurs when a user visits a specially crafted website designed to exploit a flaw in the browser's graphics engine. Such an attack could lead to the exposure of private data or help an attacker bypass security protections to gain further control over the system.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on macOS. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read memory outside of the intended buffer. This can lead to the disclosure of sensitive information from the process memory or be used as a primitive in a multi-stage exploit to bypass address space layout randomization (ASLR). The vulnerability is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-04-07: disclosed: Reported to Chrome by Google researchers
  • 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53/54
  • 2026-06-04: advisory: NVD publication date

References

Related threats