Executive brief
A critical security vulnerability has been identified in Google Chrome's graphics engine. By tricking a user into visiting a specially crafted website, a remote attacker could bypass security boundaries to access sensitive data from other open websites or tabs. This flaw compromises the fundamental 'same-origin' security model that prevents websites from spying on each other.
Technical details
An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome. The flaw is triggered when processing a maliciously crafted HTML page, leading to memory corruption or improper bounds checking. A remote, unauthenticated attacker can exploit this to bypass cross-origin resource sharing (CORS) protections and leak sensitive data from other origins. The vulnerability is addressed in Chrome version 148.0.7778.216 and later. Google has classified this as a Critical severity issue.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-04-25: disclosed: Reported by Google researchers internally
- 2026-05-27: patched: Fixed in Stable Channel Update 148.0.7778.216/217
- 2026-05-28: advisory: NVD publication date