Junglewise Threat Intelligence

CVE-2026-13859: Google Chrome sandbox escape in ANGLE

CVE-2026-13859 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's ANGLE component, which is responsible for translating graphics instructions. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could potentially bypass the browser's security sandbox, which is designed to prevent malicious websites from interacting with the rest of the computer.

Technical details

An inappropriate implementation vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome prior to version 150.0.7871.47. The flaw allows a remote attacker to potentially achieve a sandbox escape by enticing a user to visit a malicious website containing a crafted HTML page. While specific root cause details are restricted, the vulnerability is classified by Chromium as Medium severity and involves the graphics translation layer. A successful exploit could allow code execution outside of the restricted renderer process. Users are advised to update to Chrome version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats