Executive brief
A vulnerability exists in Google Chrome's ANGLE component, which is responsible for processing graphics. By tricking a user into visiting a specially crafted website, an attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data.
Technical details
A type confusion vulnerability (CWE-843) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw is triggered when the engine accesses a resource using an incompatible type, which can be induced by a remote attacker through a specially crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing code execution outside of the restricted browser environment. The vulnerability was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-28: disclosed: Reported to the Chromium project
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date