Description
Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds memory read has been identified in ANGLE, the graphics abstraction layer used by Google Chrome on macOS, prior to version 149.0.7827.53. The flaw allows a remote attacker, by serving a crafted HTML page, to read arbitrary data from the process address space. While the vulnerability does not provide direct code execution, the ability to read privileged memory can lead to leakage of sensitive information such as credentials or cryptographic material. The weakness is classified as CWE‑125, indicating an array bounds missing boundary check. The description lists the severity as High, reflecting the potential impact on confidentiality.

Affected Systems

The affected product is Google Chrome for macOS. Versions less than 149.0.7827.53 are impacted. The advisory does not quantify earlier versions; users should assume all prior releases carry the vulnerability until updates are applied. Vendors other than Google are not mentioned, and the CWE list confirms a single specific weakness in the ANGLE component.

Risk and Exploitability

The CVSS score is not provided, but the advisory labels the issue as High, and the EPSS score is currently unavailable. The vulnerability is listed outside of the CISA KEV catalog, so no widely known exploits have been reported at the time of this analysis. Based on the description, the likely attack vector is a remote, web‑based attack where an adversary hosts a malicious webpage and lures a user to visit it. Given the nature of the flaw, exploitation requires only standard browsing behavior, making the risk of compromise significant for users who frequently visit untrusted sites.

Generated by OpenCVE AI on June 5, 2026 at 02:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later
  • Enable Chrome’s site isolation and sandboxing features to limit inter-process memory exposure
  • Apply an enterprise web‑filtering policy to block high‑risk or untrusted websites until the patch is installed

Generated by OpenCVE AI on June 5, 2026 at 02:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE on macOS

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:03:43.446Z

Reserved: 2026-06-04T17:06:08.900Z

Link: CVE-2026-10930

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:16:55.440

Modified: 2026-06-04T23:16:55.440

Link: CVE-2026-10930

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T02:45:29Z

Weaknesses