Junglewise Threat Intelligence

CVE-2026-14385: Google Chrome heap buffer overflow in ANGLE

CVE-2026-14385 · Severity: info · CVSS 8.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Mac could allow a malicious website to compromise the browser's memory. By tricking a user into visiting a specially crafted webpage, an attacker could potentially crash the browser or execute unauthorized code. This poses a risk to the confidentiality of user data and the overall stability of the application.

Technical details

A heap-based buffer overflow (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The vulnerability is triggered when the browser processes a specially crafted HTML page, leading to out-of-bounds memory access. A remote, unauthenticated attacker can exploit this flaw by enticing a user to visit a malicious website. Successful exploitation could result in arbitrary code execution within the context of the browser process or a denial-of-service condition. The issue is resolved in Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released for Mac
  • 2026-07-01: disclosed: CVE-2026-14385 published

References

Related threats