Executive brief
A vulnerability in Google Chrome for Mac could allow a malicious website to access sensitive information from the browser's memory. This occurs due to a technical error in how the browser handles graphics processing. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the exposure of private data from other open tabs or browser processes.
Technical details
An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome on macOS. The flaw is triggered when processing a specially crafted HTML page, leading to an out-of-bounds memory access. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This issue is tracked as CWE-472 (External Control of Assumed-Immutable Web Parameter) and was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome Prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for Mac
- 2026-06-04: disclosed: CVE published