Executive brief
A vulnerability in Google Chrome's graphics engine (ANGLE) could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website. While the attack is initially confined to the browser's security sandbox, it represents a significant step toward full system compromise or unauthorized data access.
Technical details
An out-of-bounds memory access vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution within the context of the browser's sandboxed process. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Chrome Stable channel update released
- 2026-05-28: disclosed: NVD publication date