Executive brief
A vulnerability exists in Google Chrome for Windows within the ANGLE graphics engine. A remote attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to bypass the browser's security sandbox. This could lead to unauthorized access to the underlying operating system and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows. The flaw is triggered when the browser improperly handles memory objects during graphics rendering, which can be exploited via a maliciously crafted HTML page. A successful exploit could allow a remote attacker to execute code outside of the Chrome renderer sandbox. The vulnerability is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72 for Windows.
- 2026-07-30: disclosed: NVD publication date.