Executive brief
A vulnerability in Google Chrome for Mac could allow a malicious website to compromise the browser's memory. By tricking a user into visiting a specially crafted webpage, an attacker could potentially crash the browser or execute unauthorized code. This poses a risk to the confidentiality of user data and the overall stability of the application.
Technical details
A heap-based buffer overflow (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to out-of-bounds memory access. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a malicious website. Successful exploitation could result in arbitrary code execution within the context of the browser process or a denial-of-service condition. The issue is resolved in Chrome version 150.0.7871.46 and later.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released for Mac
- 2026-07-01: disclosed: CVE-2026-14385 published