Executive brief
A security vulnerability was identified in Google Chrome's graphics engine (ANGLE). If a user visits a malicious website, an attacker who has already partially compromised the browser's rendering process could use this flaw to break out of the security sandbox. This could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw can be triggered via a specially crafted HTML page. While the attack requires the renderer process to be previously compromised, a successful exploit allows the attacker to perform a sandbox escape, potentially leading to full system compromise. The vulnerability was addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE published to NVD.