Junglewise Threat Intelligence

CVE-2026-14398: Google Chrome use after free in ANGLE

CVE-2026-14398 · Severity: info · CVSS 9.8 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's ANGLE component, which handles graphics processing. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass the browser's security sandbox. This could lead to unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 150.0.7871.46. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics content, which can be exploited by a remote attacker via a malicious HTML page. Successful exploitation could allow an attacker to escape the Chrome renderer sandbox and execute arbitrary code on the host system. Google has addressed this issue in the stable channel update 150.0.7871.46 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel
  • 2026-07-01: advisory: NVD publication date

References

Related threats