Executive brief
A vulnerability in Google Chrome's graphics engine could allow a malicious website to corrupt the browser's memory. This occurs when the browser processes a specially crafted web page, potentially leading to a program crash or unauthorized code execution. Users are advised to update to the latest version of Chrome to protect their data and system stability.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the engine improperly handles memory boundaries during graphics rendering, which can be reached by a remote attacker through a specially crafted HTML page. Successful exploitation can lead to heap corruption, potentially allowing for arbitrary code execution within the browser's sandbox or causing a denial-of-service (crash). The issue was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop versions.
- 2026-05-28: disclosed: CVE published to the NVD.