Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics translation engine (ANGLE) allows a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could lead to unauthorized access to data or further system compromise.
Technical details
A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics content, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website, a remote attacker can exploit this condition to achieve arbitrary code execution within the renderer process sandbox. The vulnerability is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date