Junglewise Threat Intelligence

CVE-2026-8554: Google Chrome type confusion in ANGLE

CVE-2026-8554 · Severity: low · CVSS 3.1 · Published 2026-05-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. An attacker who has already partially compromised the browser's rendering process could use a specially crafted webpage to perform unauthorized memory operations. This could lead to further instability or help an attacker gain deeper control over the affected system.

Technical details

A type confusion vulnerability (CWE-843) exists in ANGLE, the graphics engine abstraction layer used by Google Chrome. The flaw is present in versions prior to 148.0.7778.168 on Windows. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this issue by enticing a user to visit a malicious HTML page. Successful exploitation allows for an out-of-bounds memory write, which can be leveraged to escape the sandbox or achieve further compromise of the host system. Google has addressed this in the Stable channel update 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2026-04-03: other: Reported to Chrome by Google researchers
  • 2026-05-12: patched: Stable channel update released for Windows
  • 2026-05-14: disclosed: NVD publication date

References

Related threats