Description
Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow in the ANGLE graphics subsystem of Google Chrome allows a remote attacker to cause Chrome to read memory beyond the intended bounds when rendering a specially crafted HTML page. The overflow can result in arbitrary memory disclosure, potentially exposing sensitive data loaded in the browser process. The weakness is a classic integer overflow, mapped to CWE‑472 and CWE‑190, and the Chromium security team rates the severity of the issue as medium. Based on the description, the attack vector is inferred to be remote via a crafted HTML page that the victim must load in Chrome.

Affected Systems

Google Chrome on Windows prior to version 147.0.7727.138 is affected. The vulnerability is present in all Windows builds of Chrome that have not applied the update component that fixes the ANGLE overflow. Only systems running Windows and Chrome before the stated version need remediation. This inference is drawn from the specified affected versions and vendor/product list.

Risk and Exploitability

Based on the description, the attack vector is remote and requires the victim to load a maliciously crafted web page. The exploit is client‑side and does not require network privileges beyond normal browser access. The EPSS score is 0.00011, indicating a very low probability of exploitation. The vulnerability is not currently listed in CISA’s KEV catalog. The CVSS score of 4.3 indicates that while the vulnerability does not provide direct remote code execution, it can lead to information disclosure. Once the crafted page is rendered in a user’s Chrome session, the attacker could read arbitrary memory content, potentially leaking confidential data.

Generated by OpenCVE AI on April 30, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 147.0.7727.138 or later; this patch corrects the integer overflow in ANGLE and prevents out‑of‑bounds memory reads.
  • If updating Chrome immediately is not possible, launch Chrome with the command‑line flag "--disable-gpu" to minimize ANGLE usage and reduce the attack surface.
  • Until the official patch is applied, avoid visiting untrusted or unknown web pages in Chrome, as the vulnerability requires a crafted HTML page to be rendered.

Generated by OpenCVE AI on April 30, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6239-1 chromium security update
History

Thu, 30 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 29 Apr 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 29 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in ANGLE Allows Remote Out‑of‑Bounds Memory Read in Google Chrome on Windows chromium-browser: Integer overflow in ANGLE
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

threat_severity

Moderate


Wed, 29 Apr 2026 02:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in ANGLE Allows Remote Out‑of‑Bounds Memory Read in Google Chrome on Windows

Wed, 29 Apr 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 28 Apr 2026 23:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in ANGLE in Google Chrome on Windows prior to 147.0.7727.138 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-29T13:07:44.052Z

Reserved: 2026-04-28T20:02:35.762Z

Link: CVE-2026-7340

cve-icon Vulnrichment

Updated: 2026-04-29T13:07:35.355Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-28T23:16:21.583

Modified: 2026-04-30T16:36:51.797

Link: CVE-2026-7340

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-04-28T00:00:00Z

Links: CVE-2026-7340 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T04:15:26Z

Weaknesses