Junglewise Threat Intelligence

CVE-2026-10999: Google Chrome integer overflow in ANGLE

CVE-2026-10999 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

An integer overflow vulnerability exists in the ANGLE graphics engine within Google Chrome on Windows. This flaw could allow a remote attacker who has already compromised the browser's rendering process to access sensitive information from the computer's memory. Users are protected by updating to the latest version of the Chrome browser.

Technical details

An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome for Windows prior to version 149.0.7827.53. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this overflow to perform an out-of-bounds memory read, potentially leaking sensitive information from the process memory. This vulnerability is mitigated by Chrome's multi-process architecture but represents a significant step in a multi-stage exploit chain. The issue is resolved in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE-2026-10999 published

References

Related threats