CVE-2026-9928

8.8

Google · Chrome

An out-of-bounds read vulnerability in the ANGLE graphics library of Google Chrome on Windows may allow for information disclosure or potential code execution.

Executive summary

Google Chrome on Windows versions prior to 148.0.7778.216 contain an out-of-bounds read vulnerability in the ANGLE library, necessitating an immediate security update.

Vulnerability

This is an out-of-bounds read (CWE-125) flaw within the ANGLE graphics component. It is a non-authenticated vulnerability requiring user interaction through a malicious web page.

Business impact

This vulnerability could allow an attacker to read sensitive memory or potentially lead to further exploitation within the browser environment. With a CVSS score of 8.8, the vulnerability is highly significant, as it could be combined with other flaws to compromise the host system on Windows platforms.

Remediation

Immediate Action: Update Google Chrome on all Windows systems to version 148.0.7778.216 or later.

Proactive Monitoring: Monitor for unusual graphics-related crashes or errors in browser logs that may indicate attempts to trigger memory read vulnerabilities.

Compensating Controls: Ensure that Windows-level security features, such as Hardware-enforced Stack Protection and DEP, are enabled to provide defense-in-depth against memory-based attacks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for this graphics-related vulnerability to facilitate further exploitation, immediate patching is required. Security teams should verify that all Windows endpoints running Chrome have been updated to the latest stable version to mitigate this risk.

More Google CVEs