Junglewise Threat Intelligence

CVE-2026-17695: Google Chrome ANGLE sandbox escape on Mac

CVE-2026-17695 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Mac contains a security vulnerability in its ANGLE graphics engine, which is responsible for translating graphics commands. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass the browser's security sandbox, potentially gaining unauthorized access to the underlying operating system and user data.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists within the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for macOS. The flaw is reachable via a specially crafted HTML page, allowing a remote, unauthenticated attacker to bypass the browser's sandbox environment. A successful sandbox escape could lead to arbitrary code execution on the host system with the privileges of the user. The issue was addressed in Google Chrome version 151.0.7922.72 for Mac.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-28: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats