Junglewise Threat Intelligence

CVE-2026-9910: Google Chrome out of bounds memory access in ANGLE

CVE-2026-9910 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine (ANGLE) could allow an attacker to execute malicious code on a user's computer. This occurs when a user visits a specially crafted website. While the attack is initially confined to the browser's security sandbox, it represents a significant step toward full system compromise or unauthorized data access.

Technical details

An out-of-bounds memory access vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to achieve arbitrary code execution within the context of the browser's sandboxed process. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Chrome Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats