Executive brief
Google Chrome, a widely used web browser, contains a critical security vulnerability in its ANGLE graphics engine. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass the browser's security sandbox, potentially allowing them to gain unauthorized access to the underlying operating system and user data.
Technical details
A critical vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome due to improper input validation (CWE-20). The flaw allows a remote attacker to bypass the browser's sandbox environment by enticing a user to visit a malicious HTML page. This sandbox escape could lead to arbitrary code execution on the host system with the privileges of the user. The vulnerability was reported by Google and is addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Access to specific bug details remains restricted to prevent further exploitation until a majority of users have updated.
Affected products
- Google Chrome Prior to 151.0.7922.72
Timeline
- 2026-06-11: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date