Executive brief
Google Chrome, a widely used web browser, contained a vulnerability in its ANGLE graphics engine. An attacker who has already partially compromised the browser's rendering process could use this flaw to break out of the security sandbox. If successful, this could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
An out-of-bounds (OOB) read and write vulnerability (CWE-787) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is accessible via a crafted HTML page. A successful exploit requires the attacker to have already compromised the renderer process (a significant precondition). Once achieved, the attacker can leverage this OOB memory access to potentially perform a sandbox escape, leading to code execution outside the restricted browser environment. The issue is resolved in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome Prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched