Executive brief
A vulnerability in Google Chrome's graphics engine could allow a malicious website to access sensitive information from the browser's memory. This issue specifically affects users on Windows and requires the attacker to have already partially compromised the browser's rendering process. Users should update to the latest version of Chrome to mitigate this risk.
Technical details
An integer overflow vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Windows. The flaw is triggered when a remote attacker, who has already achieved code execution within a compromised renderer process, uses a specially crafted HTML page to induce the overflow. This allows the attacker to bypass memory safety boundaries and read potentially sensitive information from the process memory. The issue was addressed in Chrome version 150.0.7871.46.
Affected products
- Google Chrome Prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released for Windows
- 2026-07-01: advisory: NVD publication date