Junglewise Threat Intelligence

CVE-2026-11066: Google Chrome sandbox escape in ANGLE

CVE-2026-11066 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its ANGLE graphics component could allow a malicious website to bypass the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data beyond the normal restrictions of a web page.

Technical details

An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker to bypass sandbox restrictions by enticing a user to visit a specially crafted HTML page. By providing malicious input that is insufficiently validated by the graphics engine, an attacker can potentially execute code outside of the browser's isolated sandbox environment. This vulnerability was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE published in NVD.

References

Related threats