Executive brief
A security vulnerability exists in Google Chrome's graphics translation layer (ANGLE). A remote attacker could execute malicious code on a user's computer simply by convincing them to visit a specially crafted website. This could lead to a complete compromise of the user's browser session and potentially the underlying system.
Technical details
An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker to bypass security boundaries and execute arbitrary code by providing specifically crafted untrusted input through a malicious HTML page. The vulnerability is triggered during the processing of graphics-related content. Google has addressed this issue in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: NVD publication date