Executive brief
A vulnerability in Google Chrome's graphics layer could allow a malicious website to access memory locations it should not be able to reach. This occurs when the browser processes a specially crafted webpage, potentially allowing an attacker to read sensitive information from the browser's memory. Users are protected by updating to the latest version of Chrome.
Technical details
An out-of-bounds memory access vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass memory safety boundaries. This can lead to the disclosure of sensitive information from the process memory or potentially cause a crash. The vulnerability is addressed in Chrome version 149.0.7827.53 and later. Exploitation requires the victim to visit a malicious website (User Interaction).
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE-2026-11191 published