Description
Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow in Google Chrome’s ANGLE graphics component. In versions prior to 148.0.7778.216, a specially crafted HTML page can cause the renderer process to perform an out‑of‑bounds memory read. The CVE description does not specify which data can be obtained, but such a read could potentially expose sensitive information present in the renderer’s memory.

Affected Systems

All desktop installations of Google Chrome running a version earlier than 148.0.7778.216 are affected, independent of operating system. The integer overflow flaw is fixed in Chrome 148.0.7778.216 and later releases.

Risk and Exploitability

The CVSS score of 4.3 places the flaw in the low‑to‑moderate range, while an EPSS score of less than 1% indicates a very low likelihood of widespread exploitation. The issue is not listed in CISA KEV. An attacker would need only to deliver a crafted page to a victim’s browser; no publicly available exploit is known. The out‑of‑bounds read provides a basic data‑exfiltration primitive that could be leveraged against a user who visits untrusted sites.

Generated by OpenCVE AI on May 29, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or later.
  • If an update cannot be applied immediately, limit browsing to trusted sites or use an alternative browser that is not affected by this issue.
  • Implement a content filter or firewall rule to block the delivery of malicious HTML content to the browser until the fix is installed.

Generated by OpenCVE AI on May 29, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6316-1 chromium security update
History

Mon, 01 Jun 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Read via Integer Overflow in ANGLE of Google Chrome chromium-browser: Integer overflow in ANGLE
Weaknesses CWE-190
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Important


Fri, 29 May 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Read via Integer Overflow in ANGLE of Google Chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Integer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T17:49:12.305Z

Reserved: 2026-05-28T17:24:49.531Z

Link: CVE-2026-9911

cve-icon Vulnrichment

Updated: 2026-05-29T17:49:08.207Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:49.197

Modified: 2026-06-01T18:46:29.307

Link: CVE-2026-9911

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9911 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T20:15:07Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound

  • CWE-472

    External Control of Assumed-Immutable Web Parameter