Chromium ANGLE Component Heap Buffer Overflow (CVE-2025-10502)
CVE-2025-10502 is a heap buffer overflow vulnerability in the Chromium ANGLE graphics engine that could allow an attacker to trigger memory corruption or achieve arbitrary code execution via a malicious webpage.
CVE search metadata
CVE search record: CVE-2025-10502. Severity: high. CVSS: 8.8. EPSS: 0.28%. KEV: no. Product: Chrome (< 140.0.7339.185). Brief: Chromium ANGLE Component Heap Buffer Overflow (CVE-2025-10502). Brief link: https://feed.craftedsignal.io/briefs/2026-10-chromium-angle-overflow/
CVE-2025-10502 identifies a heap buffer overflow vulnerability residing within the ANGLE (Almost Native Graphics Layer Engine) component of the Chromium project. ANGLE is used by Chromium-based browsers to translate OpenGL ES calls into underlying graphics APIs such as Direct3D or Metal. This vulnerability is significant because heap buffer overflows in graphics rendering engines often provide a pathway for remote code execution (RCE) if an attacker can successfully manipulate the browser rendering process memory. Because this engine is deeply integrated into the browser's execution pipeline, processing maliciously crafted graphics data can lead to memory corruption, potentially crashing the rendering process or facilitating sandbox escape in specific configurations. Defenders should prioritize updating any Chromium-based applications to the latest security patch provided by the vendor.
Impact
Successful exploitation of this vulnerability allows an attacker to cause an application crash or potentially execute arbitrary code within the context of the user's browser. If exploited, it could result in full browser compromise, sensitive data exfiltration from the browser's memory space, or further lateral movement into the host system. This vulnerability affects all Chromium-based browsers on Windows, macOS, and Linux platforms.
Recommendation
Prioritize the deployment of vendor-supplied browser updates across all endpoint assets. Monitor for anomalous browser process crashes or unusual activity emanating from web-rendering sub-processes (often labeled as 'renderer' or 'gpu' processes) which may indicate exploitation attempts.
Immediate actions
Update Chrome to 140.0.7339.185 or later
Mitigations
Upgrade browser installations to the version containing the fix for CVE-2025-10502
CVE-2025-10502