Junglewise Threat Intelligence

CVE-2026-13883: Google Chrome type confusion in ANGLE

CVE-2026-13883 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which is responsible for translating graphics instructions. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data.

Technical details

A type confusion vulnerability (CWE-843) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the engine accesses a resource using an incompatible type, which can be induced by a remote attacker through a specially crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing code execution outside of the restricted browser environment. The vulnerability was addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats