Junglewise Threat Intelligence

CVE-2026-78906: Google Chrome race condition in ANGLE sandbox escape

CVE-2026-78906 · Severity: high · CVSS 7.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition in ANGLE (the graphics rendering library used by Chrome) allows an attacker to bypass the browser's sandbox security boundary and execute arbitrary code. An attacker can trigger this vulnerability by crafting a malicious HTML page, leading to potential system compromise and unauthorized code execution outside the sandbox protection.

Technical details

A race condition exists in ANGLE, Chrome's graphics abstraction layer, in versions prior to 152.0.7977.65. The vulnerability allows an attacker to execute arbitrary code outside the browser sandbox through a crafted HTML page. The race condition creates a window where concurrent operations can violate ANGLE's state invariants, enabling memory corruption and code execution. No special privileges or user interaction beyond visiting a malicious page is required. The vulnerability was patched in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats