Executive brief
A vulnerability exists in Google Chrome for Android within the ANGLE graphics engine. This flaw could allow a malicious website to bypass the browser's security sandbox if the attacker has already gained initial control over the page rendering process. Successfully exploiting this could lead to unauthorized access to the underlying Android operating system or user data beyond the browser's normal restrictions.
Technical details
A use-after-free (UAF) vulnerability (CWE-416) exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome for Android. The vulnerability is reachable via a crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this memory corruption flaw to escape the sandbox and execute code with higher privileges. The issue is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed