Executive brief
A vulnerability exists in Google Chrome's ANGLE graphics engine that could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website, provided the attacker has already gained a foothold in the browser's rendering process. Such an attack could lead to the theft of sensitive data or full system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. By exploiting this memory corruption issue, an attacker can achieve arbitrary code execution within the context of the browser. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: NVD publication date