Description
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-05-28
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow in the ANGLE graphics abstraction layer used by Google Chrome. A crafted HTML page can trigger the flaw and allow a remote attacker to read potentially sensitive data from Chrome’s process memory. The issue is identified as CWE-190 and CWE-472 and is rated as Medium severity by Chromium security teams.

Affected Systems

Google Chrome versions prior to 148.0.7778.216, including all stable channel releases before that version, are vulnerable to the flaw. Users running earlier stable builds are at risk until they update to a patched release.

Risk and Exploitability

Exploit details are not publicly disclosed, and the EPSS score is not available, but the vulnerability is not listed in CISA KEV. The CVSS score is 6.5, indicating medium severity. Although a remote attacker would need to load a malicious page in the victim’s browser, the risk is moderate because the flaw only permits memory disclosure rather than full code execution. Until Chrome receives an advisory indicating active exploitation, the primary risk remains exposure of private data through crafted web content.

Generated by OpenCVE AI on May 29, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 148.0.7778.216 or newer.
  • Enable automatic updates or regularly check for new Chrome releases to stay protected.
  • Use safe browsing and web filtering to reduce exposure to malicious sites until the patch is applied.

Generated by OpenCVE AI on May 29, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in ANGLE Allows Memory Disclosure via Crafted Web Page chromium-browser: Integer overflow in ANGLE
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 28 May 2026 23:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in ANGLE Allows Memory Disclosure via Crafted Web Page
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T16:41:34.723Z

Reserved: 2026-05-28T17:25:15.437Z

Link: CVE-2026-10018

cve-icon Vulnrichment

Updated: 2026-05-29T16:41:31.450Z

cve-icon NVD

Status : Modified

Published: 2026-05-28T23:16:43.680

Modified: 2026-05-29T18:16:30.143

Link: CVE-2026-10018

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-10018 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T14:15:37Z

Weaknesses