Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine component (ANGLE) could allow a malicious website to read sensitive information from the browser's memory. This could lead to the exposure of private data or help an attacker bypass security protections.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read data beyond the intended buffer in process memory. This can lead to information disclosure, potentially revealing sensitive process data or memory layout information that could be used to facilitate further attacks. The vulnerability is reachable via the network without prior authentication, though it requires the victim to visit a malicious site. Google has addressed this in version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for Windows, Mac, and Linux.
- 2026-05-28: disclosed: NVD publication date.