Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw in its graphics processing component (ANGLE). An attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass the browser's security sandbox, potentially gaining unauthorized access to the underlying operating system and user data.
Technical details
An integer overflow vulnerability (CWE-190) exists in ANGLE, the graphics engine abstraction layer used by Google Chrome. The flaw is triggered when processing specially crafted HTML content, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website. Successful exploitation could allow the attacker to escape the Chrome renderer sandbox and execute arbitrary code on the host system. The vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome Prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date