Executive brief
Google Chrome is a widely used web browser. A vulnerability was identified in its ANGLE component, which handles graphics rendering. If exploited, this flaw could allow a remote attacker to bypass the browser's security sandbox, potentially leading to unauthorized access to the underlying operating system or user data.
Technical details
An integer overflow vulnerability (CWE-190) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is reachable via a crafted HTML page. A remote attacker who has already compromised the renderer process can exploit this overflow to potentially perform a sandbox escape. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-26: disclosed: Reported to Google
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date