Executive brief
A security vulnerability exists in Google Chrome for Android within the ANGLE graphics layer. An attacker who has already compromised a browser's rendering process could use this flaw to escape the security sandbox by tricking a user into visiting a specially crafted website. This could lead to full control over the affected device and unauthorized access to sensitive user data.
Technical details
A heap-based buffer overflow (CWE-122) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Android. The vulnerability is reachable via a crafted HTML page. A precondition for successful exploitation is that the attacker must have already compromised the renderer process. If achieved, this flaw allows the attacker to bypass the Chrome sandbox, potentially leading to arbitrary code execution at the privilege level of the browser application. The issue is resolved in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-04-07: disclosed: Reported to Chromium project by Google internal researchers
- 2026-06-02: patched: Fixed in stable channel update 149.0.7827.53
- 2026-06-04: advisory: NVD publication date