Executive brief
A security vulnerability exists in Google Chrome's ANGLE component, which handles graphics rendering. If an attacker has already compromised a browser's rendering process, they could use this flaw to escape the browser's security sandbox by tricking a user into visiting a malicious website. This could allow the attacker to gain broader access to the underlying operating system and user data.
Technical details
This vulnerability is classified as an uninitialized use (CWE-457) within ANGLE, the graphics engine abstraction layer used by Google Chrome. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within a compromised renderer process can exploit this issue to bypass sandbox restrictions and potentially execute code in the context of the browser process or the underlying OS. The vulnerability was addressed in Chrome version 150.0.7871.46 for Linux and 150.0.7871.46/.47 for Windows and Mac.
Affected products
- Google Chrome Prior to 150.0.7871.46
Timeline
- 2026-06-30: patched: Chrome 151 promoted to stable channel; version 150.0.7871.46 released with fixes.
- 2026-07-01: advisory: NVD published CVE-2026-14413.