Description
Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a type‑confusion vulnerability in ANGLE that allows a crafted HTML page to access memory beyond an intended boundary. This can corrupt data structures on the stack or heap, and if an attacker can influence the corrupted data, the impact could extend to executing arbitrary code or causing a denial‑of‑service. The weakness is classified as CWE‑843, which specifically describes type confusion problems where differing data types are incorrectly interpreted as the same type.

Affected Systems

Google Chrome on Windows users running any version prior to 149.0.7827.53 are affected. Versions of the browser that incorporate ANGLE under the Chromium engine before the mentioned patch are vulnerable. Later stable releases (149.0.7827.53 and newer) contain the fix.

Risk and Exploitability

The CVE is marked as high severity by Chromium’s internal scoring, but no public EPSS data is available. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not a known exploited vulnerability in the wild. Attackers would need to trick a user into opening a maliciously crafted web page while Chrome is running on Windows; the conditions for successful exploitation include a user or process that renders the page in a context where ANGLE is used. Given its nature as an out‑of‑bounds memory access, the risk is significant should an exploit be developed, but the current lack of evidence of active exploitation lowers the confidence in an immediate real‑world threat.

Generated by OpenCVE AI on June 5, 2026 at 05:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 149.0.7827.53 or later, which contains the ANGLE type‑confusion fix
  • Configure Chrome to receive updates automatically and use the stable channel to receive future critical security patches without manual intervention
  • Limit user access to untrusted websites or internal web content that could contain malicious HTML while the patch is applied

Generated by OpenCVE AI on June 5, 2026 at 05:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:03:54.408Z

Reserved: 2026-06-04T17:06:14.914Z

Link: CVE-2026-10955

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-04T23:16:58.450

Modified: 2026-06-04T23:16:58.450

Link: CVE-2026-10955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T02:30:29Z

Weaknesses