Junglewise Threat Intelligence

CVE-2026-79019: Google Chrome out of bounds write in ANGLE

CVE-2026-79019 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's ANGLE graphics library contains a memory safety flaw that can be exploited through a malicious webpage to execute malicious code outside Chrome's security sandbox. This could allow an attacker to bypass Chrome's protective isolation and gain arbitrary system access on an affected Windows computer.

Technical details

CVE-2026-79019 is an out of bounds write vulnerability in ANGLE (Almost Native Graphics Layer Engine), a graphics abstraction library used by Google Chrome for rendering. The vulnerability exists in Chrome versions prior to 152.0.7977.65 on Windows and can be triggered by a maliciously crafted HTML page served over the network without requiring user authentication. Successful exploitation allows an attacker to write data outside allocated memory boundaries, leading to code execution outside the Chrome sandbox. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Windows

Timeline

  • 2026-08-25: disclosed: CVE-2026-79019 disclosed in Chrome 152 stable channel release
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 and later

References

Related threats