Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine (ANGLE) could allow a remote attacker to access sensitive information from other websites. This occurs if a user visits a malicious website after the attacker has already gained partial control over the browser's rendering process.
Technical details
This vulnerability is classified as an uninitialized use (CWE-457) within ANGLE, the graphics abstraction layer used by Google Chrome. The flaw allows a remote attacker to leak cross-origin data, which could include sensitive information from other open tabs or web sessions. To exploit this, an attacker must first compromise the browser's renderer process and then entice a user to visit a specially crafted HTML page. The issue was addressed in Chrome version 148.0.7778.216. Google has assigned this a 'High' severity rating.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in Chrome Stable channel update 148.0.7778.216/217
- 2026-05-28: disclosed: NVD publication date