Executive brief
A vulnerability in Google Chrome's ANGLE component could allow a remote attacker to escape the browser's security sandbox. This component is responsible for translating graphics commands, and an exploit could allow an attacker who has already partially compromised the browser to gain broader access to the underlying operating system. Users are protected by updating to the latest version of Chrome.
Technical details
An integer overflow vulnerability (CWE-472) exists in ANGLE, the graphics engine abstraction layer in Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. Successful exploitation could allow the attacker to bypass sandbox restrictions and execute code with higher privileges on the host system. The issue was addressed in Google Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
- 2026-06-04: disclosed: CVE published.