Executive brief
A security vulnerability exists in Google Chrome's ANGLE component, which is responsible for translating graphics commands. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could potentially bypass the browser's security sandbox, which is designed to prevent malicious code from affecting the rest of the computer.
Technical details
A use-after-free (UAF) vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser improperly handles memory objects during graphics rendering, allowing a remote attacker to execute arbitrary code or escape the browser sandbox. The attack vector requires the victim to navigate to a malicious or compromised website (network-based, no authentication required). This vulnerability is tracked as CWE-416 and was addressed in Chrome version 150.0.7871.46.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel
- 2026-07-01: advisory: NVD published CVE-2026-14425 details