Description
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an insufficient validation of untrusted input in the ANGLE graphics layer of Google Chrome. If a remote attacker already controls the renderer process, a specially crafted HTML page can trigger a sandbox escape, allowing the attacker to execute code with privileges beyond the browser sandbox. This high‑severity weakness (CWE-20 and CWE-501) undermines system isolation and could compromise the confidentiality and integrity of the operating system.

Affected Systems

Machines running Google Chrome versions earlier than 148.0.7778.216 on any supported platform are affected, as the vulnerability resides in the ANGLE implementation included before that build number.

Risk and Exploitability

The CVSS score of 9.0 indicates a high seriousness. The EPSS score of <1% suggests a very low but non‑zero likelihood of exploitation at present. CVE-2026-9914 is not listed in CISA’s KEV catalog, and exploitation requires that the attacker first gain control of the renderer process, usually by convincing the user to visit a malicious web page or exploit a chain that opens a crafted HTML document.

Generated by OpenCVE AI on May 29, 2026 at 14:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome update 148.0.7778.216 or later to address the ANGLE validation issue
  • Configure Chrome to enforce the latest built‑in sandboxing controls via policy or enterprise settings
  • If a patch cannot be applied immediately, restrict renderer processes from executing unsafe content by implementing strict content‑security policies and network isolation for untrusted web pages

Generated by OpenCVE AI on May 29, 2026 at 14:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Insufficient ANGLE Input Validation Leading to Remote Sandbox Escape in Chrome chromium-browser: Insufficient validation of untrusted input in ANGLE
Weaknesses CWE-501
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 00:45:00 +0000

Type Values Removed Values Added
Title Insufficient ANGLE Input Validation Leading to Remote Sandbox Escape in Chrome

Fri, 29 May 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T15:55:36.455Z

Reserved: 2026-05-28T17:24:50.151Z

Link: CVE-2026-9914

cve-icon Vulnrichment

Updated: 2026-05-29T15:55:32.489Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T23:16:49.487

Modified: 2026-05-29T16:16:37.300

Link: CVE-2026-9914

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9914 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T14:45:06Z

Weaknesses