Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics translation engine (ANGLE) could allow a malicious website to read sensitive information from the computer's memory. This could lead to the exposure of private data or help an attacker bypass security protections to gain further control over the system.
Technical details
An integer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, leading to an out-of-bounds (OOB) memory read. A remote attacker can exploit this by enticing a user to visit a malicious website. This can result in the disclosure of sensitive memory contents, which may be used to facilitate further exploitation or bypass address space layout randomization (ASLR). The issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: CVE published to NVD