Junglewise Threat Intelligence

CVE-2026-13975: Google Chrome out of bounds read in ANGLE

CVE-2026-13975 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine (ANGLE) on macOS could allow a malicious website to access sensitive information from the browser's memory. This occurs if an attacker has already partially compromised the browser's rendering process, potentially leading to the exposure of private user data. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on macOS. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. Successful exploitation allows the attacker to read sensitive information from the process memory, potentially bypassing security boundaries. The issue was addressed in Google Chrome version 150.0.7871.47 for Mac.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats