CVE-2026-9941

8.8

Google · Chrome

A use-after-free vulnerability in the ANGLE graphics engine of Google Chrome allows for potential arbitrary code execution.

Executive summary

A high-severity use-after-free vulnerability in the Google Chrome ANGLE component poses a significant risk of arbitrary code execution through malicious web content.

Vulnerability

This vulnerability involves a use-after-free condition (CWE-416) within the ANGLE graphics abstraction layer. The attack is remotely exploitable against unauthenticated users, provided the user interacts with malicious content (UI:R).

Business impact

With a CVSS score of 8.8, this vulnerability represents a substantial threat to system integrity. Exploitation could allow attackers to bypass sandbox protections, leading to unauthorized access or the execution of arbitrary code within the user's security context.

Remediation

Immediate Action: Update Google Chrome to version 148.0.7778.216 or higher to resolve the flaw in the ANGLE component.

Proactive Monitoring: Regularly audit browser versions across the enterprise and monitor for unexpected browser crashes or stability issues, which can sometimes indicate exploitation attempts.

Compensating Controls: Utilize browser security policies or managed configuration to restrict access to potentially high-risk or untrusted websites where possible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Security teams should enforce the update to version 148.0.7778.216 immediately. Timely patching is the most effective defense against this category of memory corruption vulnerability.

More Google CVEs