Executive brief
A security vulnerability exists in Google Chrome for macOS within the ANGLE component, which handles graphics rendering. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's computer. While this code would be confined within the browser's security sandbox, it represents a significant risk to the integrity of the browsing session and could be used as part of a more complex attack.
Technical details
A heap-based buffer overflow (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The vulnerability is triggered when the browser processes a specially crafted HTML page, allowing a remote, unauthenticated attacker to achieve arbitrary code execution within the Chromium sandbox. The attack requires minimal user interaction (visiting a malicious URL). This issue was addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-03-16: disclosed: Reported by cinzinga
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 release
- 2026-04-08: advisory: NVD publication date