Junglewise Threat Intelligence

CVE-2026-9900: Google Chrome out of bounds write in ANGLE

CVE-2026-9900 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to break out of the browser's security sandbox. If an attacker has already compromised the browser's rendering process, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized access to local files, user data, or the installation of persistent malware.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within the sandboxed renderer process can exploit this memory corruption to escape the sandbox and execute arbitrary code with the privileges of the browser process. The vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Chrome Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats