Description
Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Published: 2026-04-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An integer overflow occurs in the ANGLE component of Google Chrome, allowing a remote attacker who has already compromised the renderer process to perform an out‑of‑bounds memory write via a specially crafted HTML page. The flaw can lead to arbitrary code execution in the context of the browser, giving the attacker the ability to execute malicious instructions with the privileges of the rendering process. The static analysis and vendor assessment categorize the vulnerability with high severity.

Affected Systems

The problem exists on Google Chrome running on Windows prior to version 146.0.7680.178. Users who have not upgraded to that or newer release are exposed. The vulnerability is specific to the Windows build of Chrome, as the relevant ANGLE implementation is used exclusively on that platform in this context.

Risk and Exploitability

The CVSS score of 7.5 indicates a high impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation today. The flaw requires that the attacker first gain control of the renderer process, most commonly by delivering malicious web content that the victim’s browser will interpret. Once the renderer has been compromised, the out‑of‑bounds memory write can be leveraged to execute arbitrary code. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog.

Generated by OpenCVE AI on April 2, 2026 at 04:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 146.0.7680.178 or later.

Generated by OpenCVE AI on April 2, 2026 at 04:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6192-1 chromium security update
History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Title chromium-browser: Integer overflow in ANGLE
First Time appeared Apple
Apple macos
Google
Google chrome
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses CWE-190
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Google
Google chrome
Linux
Linux linux Kernel
Microsoft
Microsoft windows
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

threat_severity

Important


Wed, 01 Apr 2026 05:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in ANGLE in Google Chrome on Windows prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-02T03:55:46.701Z

Reserved: 2026-03-31T20:07:11.996Z

Link: CVE-2026-5277

cve-icon Vulnrichment

Updated: 2026-04-01T13:27:34.186Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-01T05:16:00.933

Modified: 2026-04-01T16:40:22.150

Link: CVE-2026-5277

cve-icon Redhat

Severity : Important

Publid Date: 2026-03-31T00:00:00Z

Links: CVE-2026-5277 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T20:18:24Z

Weaknesses