Junglewise Threat Intelligence

CVE-2026-9877: Google Chrome use after free in ANGLE

CVE-2026-9877 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability exists in Google Chrome's ANGLE graphics engine. A remote attacker who has already compromised a browser tab's rendering process could use this flaw to escape the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is triggered via a crafted HTML page. To exploit this, an attacker must first compromise the renderer process. Once achieved, the UAF can be leveraged to bypass the Chromium sandbox, potentially leading to arbitrary code execution on the host system. The issue is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-03-26: disclosed: Reported by Google researchers
  • 2026-05-27: patched: Fixed in Stable Channel Update 148.0.7778.216/217
  • 2026-05-28: advisory: NVD publication date

References

Related threats