Description
Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read in ANGLE, the graphics abstraction layer used by Chrome, can be triggered by a crafted HTML page. An adversary who convinces an end user to load such a page can cause Chrome to read memory it should not, which in turn can lead to arbitrary code execution on the affected system. The weakness is identified as CWE-125, an out-of-bounds read that can be leveraged to compromise confidentiality, integrity, and availability of the victim’s environment.

Affected Systems

Windows users running Google Chrome versions earlier than 148.0.7778.216 are affected. The vulnerability applies to the desktop Chrome binary on all Windows operating systems, regardless of version, as the ANGLE component is used across the platform. No other operating systems or product variants are listed as impacted.

Risk and Exploitability

Chrome assigns the issue a high severity rating, with a CVSS score of 8.8. Because the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, detailed exploitation probability is unknown, but the remote code execution possibility and the ease of deployment via a malicious web page make the risk significant. The vulnerability is likely to be exploitable from any network that can deliver a crafted HTML page to a user, such as public Wi‑Fi or insecure corporate networks. No specific preconditions beyond browsing a malicious page are required, so the attack can occur in a wide range of environments.

Generated by OpenCVE AI on May 29, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.216 or later to remove the ANGLE bug and eliminate the out-of-bounds read.
  • If an upgrade cannot be performed immediately, disable ANGLE or the affected Chrome feature through command-line flags or the browser’s internal settings, though this may reduce graphics performance and is not a guaranteed fix.
  • Implement an enterprise web-filtering policy that blocks or warns against suspicious or untrusted web content to reduce the chance that users load malicious pages.

Generated by OpenCVE AI on May 29, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Fri, 29 May 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Remote Code Execution via Crafted HTML Page chromium-browser: Out of bounds read in ANGLE
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Fri, 29 May 2026 01:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Remote Code Execution via Crafted HTML Page
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T11:01:22.375Z

Reserved: 2026-05-28T17:24:53.108Z

Link: CVE-2026-9928

cve-icon Vulnrichment

Updated: 2026-05-29T10:46:37.294Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-28T23:16:50.900

Modified: 2026-05-29T17:49:00.253

Link: CVE-2026-9928

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9928 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T15:45:16Z

Weaknesses