Junglewise Threat Intelligence

CVE-2026-17801: Google Chrome out of bounds read and write in ANGLE

CVE-2026-17801 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's graphics engine (ANGLE) that could allow a malicious website to bypass security boundaries. By tricking a user into visiting a specially crafted webpage, an attacker could potentially escape the browser's sandbox, which is designed to isolate web content from the rest of the computer. This could lead to unauthorized access to the underlying operating system or user data.

Technical details

This vulnerability is classified as an out-of-bounds (OOB) read and write within ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to access or modify memory outside of the intended buffer. This memory corruption can be leveraged to achieve a sandbox escape, potentially leading to arbitrary code execution on the host system. The issue was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats