Junglewise Threat Intelligence

CVE-2026-78978: Google Chrome out-of-bounds read in ANGLE

CVE-2026-78978 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's ANGLE graphics rendering engine contains an out-of-bounds memory read vulnerability that affects Windows systems running versions prior to 152.0.7977.65. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited, allows code execution outside the browser's sandbox—potentially giving attackers full access to the user's system despite Chrome's security protections.

Technical details

This is an out-of-bounds read vulnerability in Google Chrome's ANGLE (Almost Native Graphics Layer Engine) graphics library on Windows prior to version 152.0.7977.65. The vulnerability is triggered when a user visits a crafted HTML page, allowing an attacker to read memory outside the intended bounds. The out-of-bounds read can be leveraged to bypass the browser sandbox and achieve arbitrary code execution with the privileges of the user running Chrome. The vulnerability was patched in Chrome 152.0.7977.65/64 released on August 25, 2026. No evidence of exploitation in the wild has been reported.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-78978 published; Chrome 152 released with patch
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats