Executive brief
A vulnerability exists in Google Chrome's ANGLE component, which handles graphics processing. A remote attacker could use a specially crafted website to trick the browser into revealing sensitive information from its memory. This could potentially lead to the exposure of private data or help an attacker bypass other security protections.
Technical details
An inappropriate implementation vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an out-of-bounds memory read or similar memory disclosure. This can result in the leakage of sensitive information from the browser's process memory to the attacker. The vulnerability is reachable over the network without prior authentication, provided the user visits a malicious site. Google has addressed this issue in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-26: disclosed: Reported to Chrome by Google internal researchers
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date