CVE-2026-10955

Google · Chrome

A Type Confusion vulnerability in the ANGLE graphics library in Google Chrome on Windows allows a remote attacker to trigger out-of-bounds memory access.

Executive summary

A Type Confusion vulnerability in the ANGLE graphics library of Google Chrome for Windows presents a risk of out-of-bounds memory access and potential system compromise.

Vulnerability

This vulnerability is a Type Confusion flaw within the ANGLE (Almost Native Graphics Layer Engine) component. An unauthenticated attacker can trigger this condition, resulting in potential out-of-bounds memory access.

Business impact

With a CVSS score of 8.8, this issue is critical for Windows-based Chrome environments. Out-of-bounds memory access can be leveraged to crash the browser or potentially achieve arbitrary code execution, which could result in the theft of user credentials or the installation of malicious software.

Remediation

Immediate Action: Update all Google Chrome instances on Windows to version 149.0.7827.53 or higher immediately.

Proactive Monitoring: Monitor for browser-related crashes or unexpected process terminations, which may indicate an attempt to exploit memory corruption vulnerabilities.

Compensating Controls: Ensure that Windows-level security features, such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR), are enabled to complicate potential exploitation attempts.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Memory corruption vulnerabilities in core components like ANGLE are frequently targeted by threat actors. It is essential to apply the provided patch to prevent unauthorized memory access and maintain the integrity of the browser environment.