Junglewise Threat Intelligence

CVE-2026-17677: Google Chrome ANGLE sandbox escape on Android

CVE-2026-17677 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Android within the ANGLE graphics engine. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying mobile operating system, potentially compromising user data or device integrity.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, potentially leading to a sandbox escape. This allows an attacker who has already achieved code execution within the renderer process to break out of the restricted environment and execute commands with the privileges of the browser application on the Android OS. The issue was addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-17: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Stable channel update released
  • 2026-07-30: advisory: NVD publication date

References

Related threats