Junglewise Threat Intelligence

CVE-2026-17676: Google Chrome for Android sandbox escape in ANGLE

CVE-2026-17676 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Android within the ANGLE graphics component. This flaw could allow a malicious website to bypass the browser's security sandbox if the attacker has already compromised the initial rendering process. A successful exploit could lead to unauthorized access to the underlying Android operating system and user data.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Android. The flaw is reachable via a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this vulnerability to perform a sandbox escape. This would allow the attacker to execute code with the privileges of the browser application on the Android operating system. The issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-17: disclosed: Reported to Chromium by Google researchers
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats