Executive brief
A security vulnerability has been identified in Google Chrome's ANGLE component, which handles graphics processing. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data, moving beyond the restricted environment where web pages normally run.
Technical details
An improper input validation vulnerability (CWE-20) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The flaw allows a remote attacker to bypass sandbox restrictions by providing malicious input through a crafted HTML page. Successful exploitation could lead to a sandbox escape, granting the attacker elevated privileges on the host system. The vulnerability is addressed in Chrome version 151.0.7922.72. Access to specific bug details remains restricted by the vendor to prevent further exploitation until a majority of users have updated.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date