Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine (ANGLE) could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is tracked as CWE-416 and resides in the renderer process. An attacker who has already achieved code execution within a compromised renderer process could exploit this memory corruption issue via a specially crafted HTML page to perform a sandbox escape. The vulnerability was addressed in Google Chrome version 150.0.7871.47 for Windows, Mac, and Linux. Chromium developers have classified this as a Low severity issue.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: Google published the stable channel update for desktop.
- 2026-06-30: patched: Fixed in version 150.0.7871.47.