Executive brief
Google Chrome's ANGLE graphics rendering engine contains an out-of-bounds memory read vulnerability that affects Windows systems running versions prior to 152.0.7977.65. An attacker can exploit this flaw by crafting a malicious HTML page that, when visited, allows code execution outside the browser's sandbox—potentially giving attackers full access to the user's system despite Chrome's security protections.
Technical details
This is an out-of-bounds read vulnerability in Google Chrome's ANGLE (Almost Native Graphics Layer Engine) graphics library on Windows prior to version 152.0.7977.65. The vulnerability is triggered when a user visits a crafted HTML page, allowing an attacker to read memory outside the intended bounds. The out-of-bounds read can be leveraged to bypass the browser sandbox and achieve arbitrary code execution with the privileges of the user running Chrome. The vulnerability was patched in Chrome 152.0.7977.65/64 released on August 25, 2026. No evidence of exploitation in the wild has been reported.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: CVE-2026-78978 published; Chrome 152 released with patch
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)