Junglewise Threat Intelligence

CVE-2026-6296: Google Chrome heap buffer overflow in ANGLE

CVE-2026-6296 · Severity: critical · CVSS 9.6 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's graphics engine. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to full system compromise and data theft.

Technical details

A heap buffer overflow vulnerability (CWE-122) exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to overflow memory in the heap. This memory corruption can be leveraged to escape the Chromium sandbox and execute arbitrary code with the privileges of the user. The vulnerability is reachable over the network without authentication, though it requires user interaction (visiting a malicious site). Google has addressed this in version 147.0.7727.101.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-03-05: other: Vulnerability reported by researcher cinzinga
  • 2026-04-15: disclosed: Vulnerability details published by NVD and Google Chrome release notes
  • 2026-04-15: patched: Fixed in Chrome version 147.0.7727.101

References