Description
Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-04
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds memory read has been identified in ANGLE, the graphics abstraction layer used by Google Chrome on macOS, prior to version 149.0.7827.53. The flaw allows a remote attacker, by serving a crafted HTML page, to read arbitrary data from the process address space. While the vulnerability does not provide direct code execution, the ability to read privileged memory can lead to leakage of sensitive information such as credentials or cryptographic material. The weakness is classified as CWE‑125, indicating an array bounds missing boundary check. The description lists the severity as High, reflecting the potential impact on confidentiality.

Affected Systems

The affected product is Google Chrome for macOS. Versions less than 149.0.7827.53 are impacted. The advisory does not quantify earlier versions; users should assume all prior releases carry the vulnerability until updates are applied. Vendors other than Google are not mentioned, and the CWE list confirms a single specific weakness in the ANGLE component.

Risk and Exploitability

The CVSS score is 8.1, and the EPSS score is < 1%. The vulnerability is listed outside of the CISA KEV catalog, so no widely known exploits have been reported at the time of this analysis. Based on the description, the likely attack vector is a remote, web‑based attack where an adversary hosts a malicious webpage and lures a user to visit it. Given the nature of the flaw, exploitation requires only standard browsing behavior, making the risk of compromise significant for users who frequently visit untrusted sites.

Generated by OpenCVE AI on June 5, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later
  • Enable Chrome’s site isolation and sandboxing features to limit inter-process memory exposure
  • Apply an enterprise web‑filtering policy to block high‑risk or untrusted websites until the patch is installed

Generated by OpenCVE AI on June 5, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6325-1 chromium security update
History

Sun, 07 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Out of bounds read in ANGLE
References
Metrics threat_severity

None

threat_severity

Important


Fri, 05 Jun 2026 21:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE on macOS

Fri, 05 Jun 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


Fri, 05 Jun 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE on macOS

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T19:33:42.164Z

Reserved: 2026-06-04T17:06:08.900Z

Link: CVE-2026-10930

cve-icon Vulnrichment

Updated: 2026-06-05T19:32:38.046Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-04T23:16:55.440

Modified: 2026-06-05T20:23:16.653

Link: CVE-2026-10930

cve-icon Redhat

Severity : Important

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-10930 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T21:30:05Z

Weaknesses