Junglewise Threat Intelligence

CVE-2026-11043: Google Chrome ANGLE out of bounds write on Mac

CVE-2026-11043 · Severity: info · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Mac within the ANGLE graphics component. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, an attacker could gain broader access to the underlying operating system, potentially leading to data theft or unauthorized control of the device.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The vulnerability is reachable via a crafted HTML page. A precondition for exploitation is that the attacker must have already compromised the renderer process. Successful exploitation allows the attacker to bypass the Chromium sandbox and execute code with the privileges of the browser process. The issue is addressed in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11043 published.

References

Related threats