Junglewise Threat Intelligence

CVE-2026-11065: Google Chrome use after free in ANGLE

CVE-2026-11065 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine (ANGLE) could allow a malicious website to escape the browser's security sandbox. This occurs if the attacker has already compromised the browser's rendering process, potentially allowing them to gain broader access to the underlying operating system. Users are protected by updating to the latest version of the Chrome browser.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics commands. A remote attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption to bypass the Chrome sandbox and execute code with the privileges of the browser process. This requires the victim to visit a malicious or compromised website. The issue is resolved in Google Chrome version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats