Junglewise Threat Intelligence

CVE-2026-17675: Google Chrome out of bounds write in ANGLE

CVE-2026-17675 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics translation engine (ANGLE) could allow a remote attacker to bypass the browser's security sandbox. If successful, an attacker who has already compromised a website's rendering process could gain broader access to the underlying system, potentially leading to data theft or unauthorized control.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw can be triggered via a specially crafted HTML page. A remote attacker who has already achieved code execution within a compromised renderer process can leverage this memory corruption to escape the Chrome sandbox and execute code with higher privileges on the host system. The vulnerability is addressed in Google Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-17: disclosed: Reported to Google internally
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats