Executive brief
A security vulnerability exists in Google Chrome for Mac within the ANGLE graphics component. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, an attacker could gain broader access to the underlying operating system, potentially leading to data theft or unauthorized control of the device.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The vulnerability is reachable via a crafted HTML page. A precondition for exploitation is that the attacker must have already compromised the renderer process. Successful exploitation allows the attacker to bypass the Chromium sandbox and execute code with the privileges of the browser process. The issue is addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE-2026-11043 published.