Junglewise Threat Intelligence

CVE-2026-9904: Google Chrome use after free in ANGLE

CVE-2026-9904 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's graphics engine (ANGLE). By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system and sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics content via a crafted HTML page. A remote, unauthenticated attacker can exploit this condition to achieve arbitrary code execution outside of the browser's sandbox environment. This vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats