Junglewise Threat Intelligence

CVE-2026-17691: Google Chrome out of bounds write in ANGLE

CVE-2026-17691 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Windows contains a security vulnerability in its graphics translation engine (ANGLE). A remote attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could potentially bypass the browser's security sandbox, which is designed to prevent malicious websites from accessing the rest of the computer's files and data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw is triggered when processing a specially crafted HTML page, allowing a remote attacker to write data outside the intended buffer boundaries. This memory corruption can be leveraged to achieve a sandbox escape, potentially leading to arbitrary code execution on the host operating system. The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-28: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats