Junglewise Threat Intelligence

CVE-2026-9953: Google Chrome out of bounds read in ANGLE

CVE-2026-9953 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine component (ANGLE) could allow a malicious website to read sensitive information from the browser's memory. This could lead to the exposure of private data or help an attacker bypass security protections.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read data beyond the intended buffer in process memory. This can lead to information disclosure, potentially revealing sensitive process data or memory layout information that could be used to facilitate further attacks. The vulnerability is reachable via the network without prior authentication, though it requires the victim to visit a malicious site. Google has addressed this in version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-05-28: disclosed: NVD publication date.

References

Related threats