Junglewise Threat Intelligence

CVE-2026-9919: Google Chrome WebGL out of bounds read

CVE-2026-9919 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebGL component, which handles 3D graphics, could allow a malicious website to read data from other open websites or the user's device. This could lead to the exposure of sensitive personal information or login sessions.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the WebGL component of Google Chrome for Android. The flaw is triggered when the browser processes specially crafted HTML content, allowing a remote attacker to read memory outside of the intended buffer. This can be exploited to bypass cross-origin isolation and leak sensitive data from other origins. The vulnerability was addressed in version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats