Executive brief
Google Chrome includes ANGLE, a graphics rendering component that translates graphics API calls. A type confusion vulnerability in ANGLE allows an attacker to craft a malicious HTML page that, when visited, can execute arbitrary code outside Chrome's security sandbox. This could lead to complete system compromise, data theft, or malware installation with the privileges of the user running the browser.
Technical details
CVE-2026-78904 is a type confusion vulnerability in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox by delivering a crafted HTML page; no authentication or user interaction beyond viewing the page is required. The attack vector is network-based, with the vulnerability exploitable via a malicious website. Type confusion occurs when the renderer incorrectly interprets an object's type, allowing an attacker to bypass type safety checks and achieve code execution. The patch was released in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux) on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)
Timeline
- 2026-08-25: disclosed: Type confusion in ANGLE disclosed in Chrome 152 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)
- 2026-08-25: other: Chromium security severity marked as High in the advisory, though reported severity is critical