Junglewise Threat Intelligence

CVE-2026-17721: Google Chrome out of bounds write in ANGLE

CVE-2026-17721 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability was identified in Google Chrome's ANGLE component, which handles graphics rendering. By convincing a user to visit a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to execute unauthorized code on the underlying operating system, compromising the security and privacy of the user's data.

Technical details

This vulnerability is classified as an out-of-bounds write (CWE-787) within ANGLE, the graphics engine abstraction layer used by Google Chrome. The flaw is triggered when the browser processes a maliciously crafted HTML page, leading to memory corruption. A remote, unauthenticated attacker can exploit this to achieve a sandbox escape, potentially gaining execution privileges outside of the restricted browser process. The issue was addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats