Junglewise Threat Intelligence

CVE-2026-11113: Google Chrome improper input validation in ANGLE

CVE-2026-11113 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's graphics component (ANGLE) could allow a remote attacker to bypass the browser's security sandbox. This occurs if an attacker first compromises the browser's rendering process, typically by tricking a user into visiting a malicious website. If successful, the attacker could gain broader access to the underlying system, potentially compromising user data or installing unauthorized software.

Technical details

An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform a sandbox escape. This is achieved via a specially crafted HTML page that exploits the insufficient validation of untrusted input within the graphics layer. Successful exploitation allows the attacker to break out of the restricted browser environment and execute commands with the privileges of the browser process. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: NVD publication date.

References

Related threats