Junglewise Threat Intelligence

CVE-2026-9899: Google Chrome use after free in ANGLE

CVE-2026-9899 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to bypass the browser's security sandbox. If an attacker has already compromised the process responsible for rendering web content, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized data access or the execution of malicious software on the user's device.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption to escape the sandbox and execute arbitrary code with the privileges of the browser process. This vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats