Executive brief
Google Chrome is a widely used web browser. A vulnerability in its ANGLE graphics engine could allow a malicious website to bypass the browser's security sandbox. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data beyond the browser's restricted environment.
Technical details
An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker to potentially achieve a sandbox escape by enticing a user to visit a specially crafted HTML page. By providing malicious input that is insufficiently validated by the graphics layer, the attacker can break out of the renderer process's restricted environment. This vulnerability was addressed in Chrome version 150.0.7871.46.
Affected products
- Google Chrome prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Fix released in Chrome 150.0.7871.46 for Desktop.
- 2026-07-01: disclosed: CVE published to NVD.