Executive brief
Google Chrome is a widely used web browser. A vulnerability in its ANGLE graphics engine allows a remote attacker to trigger memory errors by convincing a user to visit a specially crafted website. This could lead to browser crashes or potentially allow the attacker to access sensitive information or execute unauthorized code on the user's system.
Technical details
An inappropriate implementation vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows for out-of-bounds memory access when processing a specially crafted HTML page. This is a remote, network-based attack vector that requires no special privileges other than enticing a user to visit a malicious site. Successful exploitation could lead to memory corruption, potentially resulting in arbitrary code execution or information disclosure within the context of the browser process. The issue is resolved in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: CVE published to NVD