Description
Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out‑of‑bounds read in the ANGLE graphics component of Google Chrome. A remote attacker who has already compromised the renderer process can craft a malicious HTML page to trigger the read, exposing sensitive information from the browser’s process memory. The flaw does not provide arbitrary code execution, but it can lead to confidential data disclosure within the renderer’s memory space.

Affected Systems

Google Chrome running on macOS versions prior to 150.0.7871.47 is affected. Any machine that has a vulnerable Chrome installation will be exposed.

Risk and Exploitability

The CVE is rated medium severity by Chromium and is not listed in CISA’s KEV catalog. No EPSS score is available, indicating no high exploitation probability data. The flaw requires that the attacker already have compromised the renderer process, limiting the attack surface to browsers that have been manipulated or that are running untrusted content. If exploited, the impact remains within the Chrome process and affects only the confidentiality of data accessible to that renderer.

Generated by OpenCVE AI on July 1, 2026 at 02:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Chrome update 150.0.7871.47 or later on macOS to remove the ANGLE out‑of‑bounds read.
  • If an immediate update is not possible, disable ANGLE by launching Chrome with the flag --disable-angle or by setting the chrome://flags/#disable-angle option, which bypasses the vulnerable code path but may degrade rendering performance.
  • Keep Chrome’s automatic update feature enabled and regularly review release notes so that security patches are applied promptly.

Generated by OpenCVE AI on July 1, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome’s ANGLE Component on macOS Allows Sensitive Data Exposure

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-125
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:22:14.543Z

Reserved: 2026-06-29T23:04:06.026Z

Link: CVE-2026-13975

cve-icon Vulnrichment

Updated: 2026-07-01T01:22:02.696Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T02:45:03Z

Weaknesses