Junglewise Threat Intelligence

CVE-2026-9911: Google Chrome integer overflow in ANGLE

CVE-2026-9911 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics translation engine (ANGLE) could allow a malicious website to read sensitive information from the computer's memory. This could lead to the exposure of private data or help an attacker bypass security protections to gain further control over the system.

Technical details

An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds (OOB) memory read. A remote attacker can exploit this by enticing a user to visit a malicious website. This can result in the disclosure of sensitive memory contents, which may be used to facilitate further exploitation or bypass address space layout randomization (ASLR). The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats