Junglewise Threat Intelligence

CVE-2026-9944: Google Chrome uninitialized use in ANGLE

CVE-2026-9944 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine (ANGLE) could allow a remote attacker to access sensitive information from other websites. This occurs if a user visits a malicious website after the attacker has already gained partial control over the browser's rendering process.

Technical details

This vulnerability is classified as an uninitialized use (CWE-457) within ANGLE, the graphics abstraction layer used by Google Chrome. The flaw allows a remote attacker to leak cross-origin data, which could include sensitive information from other open tabs or web sessions. To exploit this, an attacker must first compromise the browser's renderer process and then entice a user to visit a specially crafted HTML page. The issue was addressed in Chrome version 148.0.7778.216. Google has assigned this a 'High' severity rating.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
  • 2026-05-28: disclosed: NVD publication date

References

Related threats