Executive brief
Google Chrome is a widely used web browser. A critical security vulnerability was found in its ANGLE graphics engine that could allow a malicious website to execute unauthorized code on a user's computer. While the browser's security sandbox limits the immediate impact, this type of flaw is often used as a stepping stone for more serious system compromises.
Technical details
A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser attempts to access memory that has already been freed, typically during the processing of complex graphical content. A remote attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation allows for arbitrary code execution within the Chromium renderer sandbox. The issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-04-02: other: Reported by Google researchers
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed