Junglewise Threat Intelligence

CVE-2026-8525: Google Chrome heap buffer overflow in ANGLE on Mac

CVE-2026-8525 · Severity: high · CVSS 8.3 · Published 2026-05-14

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

A security vulnerability exists in Google Chrome for Mac that could allow a malicious website to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted webpage, an attacker could potentially gain unauthorized access to the underlying operating system. This poses a significant risk to data confidentiality and system integrity for users of the affected browser versions.

Technical details

A heap buffer overflow vulnerability (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on macOS. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to achieve a sandbox escape, potentially executing arbitrary code with the privileges of the user. The vulnerability was addressed in Chrome version 148.0.7778.168 for Mac.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-03-30: disclosed: Reported by Nathaniel Oh (@calysteon)
  • 2026-05-12: patched: Fixed in version 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats