Junglewise Threat Intelligence

CVE-2026-9946: Google Chrome use after free in ANGLE

CVE-2026-9946 · Severity: info · CVSS 8.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine (ANGLE) that could allow a malicious website to break out of the browser's security sandbox. If an attacker has already compromised the browser's rendering process, they could use this flaw to gain broader access to the underlying operating system. This could lead to unauthorized data access or the execution of malicious software on the user's device.

Technical details

A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 148.0.7778.216. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics commands. A remote attacker who has already achieved code execution within the renderer process can exploit this memory corruption to escape the Chrome sandbox. Successful exploitation allows for arbitrary code execution on the host operating system with the privileges of the logged-in user. Users are advised to update to the latest stable channel version.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: CVE published to NVD.

References

Related threats