Junglewise Threat Intelligence

CVE-2026-9942: Google Chrome uninitialized use in ANGLE

CVE-2026-9942 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine could allow a malicious website to bypass security boundaries. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's rendering process could gain unauthorized access to data from other open websites. This undermines 'site isolation,' a core security feature designed to keep data from different websites separate and secure.

Technical details

An uninitialized variable vulnerability (CWE-457) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already achieved a compromise of the renderer process. By exploiting this uninitialized state, a remote attacker can bypass site isolation protections, potentially leading to cross-origin data access. The issue was addressed in Chrome version 148.0.7778.216.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats