Junglewise Threat Intelligence

CVE-2026-9969: Google Chrome insufficient validation of untrusted input in ANGLE

CVE-2026-9969 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's graphics translation layer (ANGLE). A remote attacker could execute malicious code on a user's computer simply by convincing them to visit a specially crafted website. This could lead to a complete compromise of the user's browser session and potentially the underlying system.

Technical details

An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker to bypass security boundaries and execute arbitrary code by providing specifically crafted untrusted input through a malicious HTML page. The vulnerability is triggered during the processing of graphics-related content. Google has addressed this issue in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats