Executive brief
A vulnerability exists in Google Chrome's ANGLE component, which is responsible for translating graphics instructions. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data.
Technical details
A type confusion vulnerability (CWE-843) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the engine accesses a resource using an incompatible type, which can be induced by a remote attacker through a specially crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing code execution outside of the restricted browser environment. The vulnerability was addressed in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched