Junglewise Threat Intelligence

CVE-2026-78989: Google Chrome out-of-bounds read in ANGLE on Windows

CVE-2026-78989 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome includes ANGLE, a graphics rendering component used on Windows to display web content. An out-of-bounds memory read vulnerability in ANGLE allows an attacker to craft a malicious web page that, when visited, could execute arbitrary code outside Chrome's security sandbox—potentially compromising the entire system. This could lead to data theft, malware installation, or full system compromise.

Technical details

CVE-2026-78989 is an out-of-bounds read vulnerability in the ANGLE graphics library within Google Chrome on Windows. The vulnerability exists in versions prior to 152.0.7977.65 and is triggered via a crafted HTML page, requiring only that a user visit a malicious website (no authentication or special privileges needed). An attacker exploiting this flaw can read memory outside the intended bounds, potentially bypassing the Chrome sandbox and achieving arbitrary code execution at the system level. The vulnerability was patched in Chrome 152.0.7977.65 and later releases.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Windows

Timeline

  • 2026-07-09: disclosed: Reported by Đặng Thế Tuyến
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 for Windows/Mac
  • 2026-08-25: advisory: Published in Chrome security update

References

Related threats