Junglewise Threat Intelligence

CVE-2026-11061: Google Chrome type confusion in ANGLE

CVE-2026-11061 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to execute unauthorized code on the user's system, compromising data privacy and system integrity.

Technical details

A type confusion vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 149.0.7827.53. The flaw is triggered when the engine incorrectly processes data types during graphics rendering, which can be exploited by a remote attacker via a malicious HTML page. Successful exploitation could lead to an out-of-bounds memory access (CWE-125) and potentially allow the attacker to escape the Chrome renderer sandbox. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Fixed in Chrome version 149.0.7827.53
  • 2026-06-04: disclosed: CVE published to NVD

References

Related threats