Executive brief
A vulnerability exists in Google Chrome's graphics layer (ANGLE) that could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's rendering process could escape the 'sandbox'—the security layer designed to keep web content isolated from the rest of the computer. This could lead to unauthorized access to the user's local system and data.
Technical details
A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics content. A remote attacker can exploit this by enticing a user to visit a malicious HTML page. If the attacker has already achieved code execution within the renderer process (e.g., via a separate V8 exploit), they can leverage this UAF to perform a sandbox escape, gaining elevated privileges on the host operating system. Google has addressed this in the stable channel update to version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome version 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11040 published.