Junglewise Threat Intelligence

CVE-2026-9908: Google Chrome out of bounds read in ANGLE

CVE-2026-9908 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability was identified in its ANGLE component, which handles graphics processing. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to access sensitive information from the browser's memory.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read memory outside of the intended buffer. This can lead to the disclosure of sensitive information from the browser's process memory. The vulnerability affects Google Chrome versions prior to 148.0.7778.216. Google has released a patch in the stable channel update to address this issue.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats