Junglewise Threat Intelligence

CVE-2026-9928: Google Chrome out of bounds read in ANGLE

CVE-2026-9928 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's ANGLE component, which handles graphics processing. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. This could lead to a full system compromise, data theft, or the installation of malicious software.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to bypass security boundaries and potentially achieve arbitrary code execution within the context of the browser process. The vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: CVE published to NVD

References

Related threats