Executive brief
A security vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass the browser's security sandbox, potentially gaining unauthorized access to the underlying operating system or user data.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote, unauthenticated attacker to trigger a sandbox escape by providing malicious input through a specially crafted HTML page. By bypassing the sandbox, the attacker could execute code with the privileges of the browser process rather than the restricted renderer process. The issue was addressed in Google Chrome version 150.0.7871.46 for Windows, Mac, and Linux.
Affected products
- Google Chrome Prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel.
- 2026-07-01: advisory: CVE published in NVD.