Junglewise Threat Intelligence

CVE-2026-9915: Google Chrome heap buffer overflow in ANGLE

CVE-2026-9915 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to break out of the browser's security sandbox. This component, known as ANGLE, is responsible for translating graphics commands for the hardware. If exploited, an attacker who has already compromised a browser tab could gain broader access to the underlying operating system and user data.

Technical details

A heap-based buffer overflow (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The vulnerability is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within the Chrome renderer process can leverage this overflow to bypass sandbox restrictions and achieve a sandbox escape. This would allow the attacker to execute arbitrary code with the privileges of the browser process on the host operating system. The issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats