Junglewise Threat Intelligence

CVE-2026-9999: Google Chrome inappropriate implementation in ANGLE on Mac

CVE-2026-9999 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's graphics engine (ANGLE) on macOS could allow a malicious website to execute unauthorized code on a user's computer. While the code execution is restricted within a security sandbox, it represents a significant breach of the browser's security boundaries. This could potentially lead to further attacks or the compromise of user data if combined with other vulnerabilities.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on macOS. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, leading to arbitrary code execution within the browser's sandbox environment. The issue stems from how ANGLE handles specific graphics instructions or state transitions. This vulnerability was addressed in Chrome version 148.0.7778.216 for Mac.

Affected products

  • Google Chrome Prior to 148.0.7778.216 on Mac

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop
  • 2026-05-28: disclosed: NVD publication date

References

Related threats