Junglewise Threat Intelligence

CVE-2026-11055: Google Chrome use after free in ANGLE

CVE-2026-11055 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering on Windows. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's computer. While the exploit is limited to the browser's security sandbox, it represents a significant risk to data privacy and system integrity if combined with other flaws.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw is triggered when the browser attempts to access memory that has already been deallocated during the processing of graphics commands. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page that, when rendered by a victim, triggers the memory corruption. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium sandbox. Google has addressed this in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update.
  • 2026-06-04: disclosed: NVD publication date.

References

Related threats