Junglewise Threat Intelligence

CVE-2026-9916: Google Chrome out of bounds write in ANGLE

CVE-2026-9916 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability was identified in Google Chrome's graphics engine (ANGLE). If a user visits a malicious website, an attacker who has already partially compromised the browser's rendering process could use this flaw to break out of the security sandbox. This could allow the attacker to gain broader access to the underlying operating system and user data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw can be triggered via a specially crafted HTML page. While the attack requires the renderer process to be previously compromised, a successful exploit allows the attacker to perform a sandbox escape, potentially leading to full system compromise. The vulnerability was addressed in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats