Description
Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A heap buffer overflow exists in the ANGLE component of Google Chrome on Windows, allowing a remote attacker who has been able to compromise the renderer process to create a crafted HTML page that could trigger the overflow. The vulnerability is classified as CWE‑120 and CWE‑122, both indicating vulnerable heap buffer behaviors, and could lead to a sandbox escape and arbitrary code execution within the Chrome environment.

Affected Systems

The flaw affects Google Chrome users on Windows running any version prior to 148.0.7778.216. Attackers would need to inject malicious content into a renderer process, typically through a web page that the user views.

Risk and Exploitability

The CVSS score is 8.2 and the EPSS score is less than 1%, indicating a high severity but a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted HTML page delivered over HTTP or HTTPS to a user browsing the web. Once the renderer is compromised, the unchecked Heap access could break the sandbox boundaries, enabling execution of arbitrary code. The overall risk is considered high, given the potential for remote code execution, but the exact probability remains uncertain due to the low EPSS score.

Generated by OpenCVE AI on May 29, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or later, which includes the fix for the ANGLE heap overflow.
  • If an immediate upgrade is not possible, run Chrome with the ‑disable-accelerated-2d-canvas or ‑disable-gpu flags to prevent ANGLE from being used, thereby reducing the attack surface.
  • Configure the browser’s Content Security Policy and enforce HTTPS for all pages to limit the ability of malicious scripts to execute or exploit the renderer process.

Generated by OpenCVE AI on May 29, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title ANGLE Heap Buffer Overflow Allows Sandbox Escape in Chrome on Windows chromium-browser: Heap buffer overflow in ANGLE
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 01:15:00 +0000

Type Values Removed Values Added
Title ANGLE Heap Buffer Overflow Allows Sandbox Escape in Chrome on Windows
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T15:50:43.230Z

Reserved: 2026-05-28T17:24:52.276Z

Link: CVE-2026-9924

cve-icon Vulnrichment

Updated: 2026-05-29T15:50:38.798Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T23:16:50.503

Modified: 2026-05-29T16:16:37.933

Link: CVE-2026-9924

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9924 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:45:16Z

Weaknesses