Description
Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-05-28
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, classified as CWE-125, is an out‑of‑bounds read that occurs during WebGL operations in Google Chrome on Android. This flaw enables a remote attacker to read memory outside the intended bounds and leak data that it should not be able to access. The attacker can trigger the flaw by serving a maliciously crafted HTML page, and the compromised data may include sensitive information from other web origins, effectively bypassing the browser’s same‑origin policy. As a result, the primary impact is the disclosure of confidential data to a malicious actor.

Affected Systems

Google Chrome for Android is affected only when the browser version is older than 148.0.7778.216. Any Chrome build before that revision is susceptible; all newer releases include the patch that eliminates the out‑of‑bounds read.

Risk and Exploitability

The vulnerability has a CVSS score of 4.3, indicating low severity, though the Chromium security scale still rates it as high. The EPSS score is < 1%, indicating a very low probability of exploitation, and it is not listed in the CISA KEV catalog, suggesting it has not yet been widely reported or observed in the wild. The attack vector requires the victim to open a maliciously crafted page in Chrome, so active user interaction is needed. Detection of exploitation would be through anomalous memory access patterns within WebGL contexts. Due to the absence of automated landscape coverage data, the exact likelihood of exploitation remains uncertain, but the potential for data leakage warrants immediate attention.

Generated by OpenCVE AI on May 29, 2026 at 20:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 148.0.7778.216 or later via the Android Play Store or an official update channel.
  • Ensure automatic updates are enabled or manually install the latest stable release to receive the WebGL fix promptly.
  • If an upgrade cannot be performed immediately, disable WebGL in chrome://flags by setting it to "Disabled" as a temporary workaround.

Generated by OpenCVE AI on May 29, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Fri, 29 May 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds read in WebGL permits cross‑origin data leakage via crafted page chromium-browser: Out of bounds read in WebGL
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Important


Fri, 29 May 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 29 May 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds read in WebGL permits cross‑origin data leakage via crafted page

Thu, 28 May 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds read in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-29T16:28:28.697Z

Reserved: 2026-05-28T17:24:56.821Z

Link: CVE-2026-9943

cve-icon Vulnrichment

Updated: 2026-05-29T16:28:25.814Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T23:16:52.433

Modified: 2026-05-29T18:17:16.017

Link: CVE-2026-9943

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-27T00:00:00Z

Links: CVE-2026-9943 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T20:15:07Z

Weaknesses