Executive brief
Google Chrome is a widely used web browser. A vulnerability in its graphics engine component (ANGLE) could allow a malicious website to bypass security boundaries known as the 'sandbox.' If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's restricted environment.
Technical details
A use-after-free (UAF) vulnerability exists in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of graphics-related content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, leading to memory corruption. This corruption can be leveraged to achieve a sandbox escape, allowing code execution outside of the browser's restricted process. The issue is fixed in Chrome version 150.0.7871.46 and later.
Affected products
- Google Chrome Prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Fix released in Chrome 150.0.7871.46 for desktop
- 2026-07-01: disclosed: CVE published to NVD