Junglewise Threat Intelligence

CVE-2026-9879: Google Chrome out of bounds write in ANGLE

CVE-2026-9879 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. By tricking a user into visiting a specially crafted website, a remote attacker could execute malicious code on the user's computer. This could lead to a total compromise of the user's browser session, theft of sensitive data, or unauthorized access to the underlying system.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this by hosting a malicious website and enticing a user to visit it. Successful exploitation allows for arbitrary code execution within the context of the browser process. The vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-04-03: disclosed: Reported by Google researchers
  • 2026-05-27: patched: Fixed in Stable Channel Update 148.0.7778.216/217
  • 2026-05-28: advisory: NVD publication date

References

Related threats