Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine component (ANGLE) could allow a malicious website to read sensitive information from the browser's memory. This occurs when a user visits a specially crafted webpage, potentially leading to the exposure of private data.
Technical details
An integer overflow vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when processing a specially crafted HTML page, leading to an out-of-bounds memory read. This is a remote, unauthenticated attack that requires user interaction (visiting a malicious site). An attacker can exploit this to read sensitive data from the browser process memory. The issue was addressed in Chrome version 147.0.7727.138 for Windows.
Affected products
- Google Chrome prior to 147.0.7727.138
Timeline
- 2026-03-30: other: Reported by researcher
- 2026-04-28: patched: Fixed in version 147.0.7727.138
- 2026-04-28: disclosed