Executive brief
A vulnerability in Google Chrome's graphics engine could allow a malicious website to break out of the browser's security sandbox. If an attacker has already compromised the browser's rendering process, they could use this flaw to gain broader access to the underlying computer system. This could lead to unauthorized data access or the execution of malicious software outside the browser's restricted environment.
Technical details
An out-of-bounds (OOB) read and write vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is reachable via a crafted HTML page and requires the attacker to have already compromised the renderer process. By exploiting this memory corruption issue, a remote attacker can bypass the Chromium sandbox to execute code with the privileges of the browser process or the underlying operating system. The vulnerability is addressed in Google Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in Chrome Stable Channel Update 148.0.7778.216/217
- 2026-05-28: disclosed: NVD publication date