Junglewise Threat Intelligence

CVE-2026-78905: Google Chrome type confusion in ANGLE

CVE-2026-78905 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics library contains a type confusion vulnerability that allows remote attackers to execute arbitrary code outside the browser sandbox by tricking users into visiting a malicious webpage. This could lead to complete system compromise, data theft, or malware installation without additional user interaction beyond visiting the malicious site.

Technical details

The vulnerability is a type confusion flaw in ANGLE (the rendering engine abstraction layer) in Google Chrome prior to version 152.0.7977.65. The type confusion occurs during graphics processing, which can lead to memory corruption and arbitrary code execution outside the sandbox. An attacker can exploit this by crafting a malicious HTML page that triggers the vulnerable code path when visited by a user. The attack requires only that the victim visit the malicious webpage (user interaction limited to browsing). The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats