Junglewise Threat Intelligence

CVE-2026-9932: Google Chrome use after free in ANGLE

CVE-2026-9932 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine on Windows could allow a malicious website to break out of the browser's security sandbox. This occurs if the attacker has already compromised the browser's rendering process, potentially leading to full control over the underlying operating system. Users are protected by updating to the latest version of the Chrome browser.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome for Windows. The flaw is reachable via a crafted HTML page and requires the attacker to have already achieved code execution within the renderer process (a 'compromised renderer'). By exploiting this memory corruption issue, an attacker can bypass the Chromium sandbox to execute arbitrary code on the host operating system. The vulnerability was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats