Junglewise Threat Intelligence

CVE-2026-17678: Google Chrome out of bounds read in ANGLE

CVE-2026-17678 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its ANGLE graphics engine. This flaw could allow a remote attacker who has already compromised a browser tab to break out of the security sandbox. If successful, this could lead to unauthorized access to the underlying operating system and the user's private data.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The vulnerability is reachable via a crafted HTML page. A remote attacker who has already achieved code execution within a compromised renderer process could leverage this flaw to perform a sandbox escape. This would allow the attacker to bypass the security boundaries intended to isolate the browser from the host operating system. The issue is resolved in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome Prior to 151.0.7922.72

Timeline

  • 2026-05-21: disclosed: Reported to Google
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats