Executive brief
A critical security vulnerability exists in Google Chrome's ANGLE component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could corrupt the browser's memory. This could lead to a complete browser crash or allow the attacker to execute unauthorized code on the user's computer, potentially compromising sensitive data or system stability.
Technical details
An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome for Windows. The flaw is triggered when processing specifically crafted HTML content, leading to an out-of-bounds (OOB) memory write. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage. Successful exploitation could result in arbitrary code execution within the context of the browser renderer process or a denial-of-service (DoS) condition. The vulnerability was addressed in Chrome version 148.0.7778.168 for Windows.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-04-01: disclosed: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date