Executive brief
A security vulnerability has been identified in Google Chrome for Windows that could allow a malicious website to break out of the browser's security sandbox. This occurs when a user visits a specially crafted webpage, potentially allowing an attacker to gain control over the underlying computer system. Google has released an update to address this issue, and users are advised to ensure their browser is updated to the latest version.
Technical details
A heap buffer overflow exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The vulnerability (CWE-122) can be triggered by a remote attacker who has already compromised the renderer process, typically via a malicious HTML page. By exploiting this memory corruption, the attacker can potentially achieve a sandbox escape, leading to arbitrary code execution on the host operating system. This issue was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: CVE-2026-9924 published.