Junglewise Threat Intelligence

CVE-2026-10955: Google Chrome type confusion in ANGLE

CVE-2026-10955 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. By tricking a user into visiting a specially crafted website, a remote attacker could gain unauthorized access to the browser's memory. This could lead to the theft of sensitive information or the execution of malicious code on the user's computer.

Technical details

A type confusion vulnerability (CWE-843) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Windows. The flaw is triggered when the engine processes incompatible data types, leading to out-of-bounds memory access. An attacker can exploit this by hosting a malicious HTML page that, when rendered by a vulnerable browser version, allows for arbitrary memory reads or writes. This can result in a sandbox escape or remote code execution. The issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome stable channel update 149.0.7827.53 released
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats