Junglewise Threat Intelligence

CVE-2026-9926: Google Chrome heap buffer overflow in ANGLE

CVE-2026-9926 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's graphics engine (ANGLE) that could allow a malicious website to break out of the browser's security sandbox. If a user visits a specially crafted webpage, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system. This could lead to unauthorized data access or the execution of malicious software on the user's computer.

Technical details

A heap buffer overflow vulnerability (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page. While the vulnerability requires a pre-existing compromise of the renderer process, it provides a mechanism for a sandbox escape, allowing an attacker to execute code outside of the restricted browser environment. This vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats