Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics translation engine (ANGLE) could allow a malicious website to cause memory errors on a user's computer. This could lead to browser instability or potentially allow an attacker to perform unauthorized actions within the browser's environment.
Technical details
An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome for Windows. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds (OOB) memory write. This is classified as CWE-472 (External Control of Assumed-Immutable Web Parameter). A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could result in memory corruption, potentially leading to a process crash or limited code execution within the sandboxed renderer process. The issue is resolved in Chrome version 148.0.7778.168.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2026-02-16: disclosed: Reported by researcher cinzinga
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date