Executive brief
A vulnerability exists in Google Chrome's ANGLE component, which is responsible for translating graphics commands. If an attacker has already compromised the browser's rendering process, they could use this flaw to access sensitive information stored in the computer's memory. This could lead to the exposure of private data from other websites or the browser itself.
Technical details
An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this lack of validation to perform out-of-bounds memory access. This allows the attacker to read sensitive information from the process memory space. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: Google released a stable channel update addressing the issue.
- 2026-06-30: disclosed: CVE published to the NVD.