Description
Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-04
Score: 9.6 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read and write in ANGLE, the graphics layer used by Chrome. This flaw can potentially lead to a sandbox escape, allowing an attacker who supplies a specially crafted HTML page to run non‑sandboxed code. The weakness is a classic out‑of‑bounds memory access that compromises integrity and confidentiality within the browser process. The official Chromium severity is listed as Critical, indicating that successful exploitation could grant full system privileges to the attacker.

Affected Systems

Google Chrome versions prior to 149.0.7827.53 are affected. The issue applies to all platforms where ANGLE is enabled, which includes the stable desktop channel of Chrome. No other browsers or products are known to be impacted.

Risk and Exploitability

The vulnerability is remotely exploitable through a web page, implying that an attacker only needs to lure a victim to a malicious site. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the CVSS score of 9.6 indicates Critical severity, suggesting a high likelihood of exploitation in the wild. The lack of an official patch notice in the input implies that users of the affected Chrome version remain at risk until they upgrade. The attack requires the victim to load the crafted page, meaning a phishing or social‑engineering vector is a typical prerequisite.

Generated by OpenCVE AI on June 5, 2026 at 07:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to a version newer than 149.0.7827.53, which contains the ANGLE fix.
  • If an immediate upgrade is not possible, disable hardware acceleration or the ANGLE graphics backend via Chrome flags to reduce the attack surface.
  • Monitor for and block known malicious HTML patterns that trigger out‑of‑bounds accesses, such as known crafted URLs or payloads, using enterprise web‑filtering or content‑disposition controls.

Generated by OpenCVE AI on June 5, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 07:45:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑Bounds Vulnerability Allowing Sandbox Escape in Chrome

Fri, 05 Jun 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read/Write in ANGLE Enabling Potential Sandbox Escape
Weaknesses CWE-122
CWE-188

Fri, 05 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read/Write in ANGLE Enabling Potential Sandbox Escape
Weaknesses CWE-122
CWE-188

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T01:29:23.207Z

Reserved: 2026-06-04T17:05:54.565Z

Link: CVE-2026-10881

cve-icon Vulnrichment

Updated: 2026-06-05T01:28:59.583Z

cve-icon NVD

Status : Received

Published: 2026-06-04T23:16:49.397

Modified: 2026-06-05T02:16:50.290

Link: CVE-2026-10881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T07:30:31Z

Weaknesses