Executive brief
An out of bounds write vulnerability in Chrome's ANGLE graphics component allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page. This could allow attackers to escape the browser security boundary and compromise the underlying system. The vulnerability affects Chrome versions before 152.0.7977.65.
Technical details
An out of bounds write vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), Chrome's graphics abstraction layer. The vulnerability can be triggered by a remote attacker through a crafted HTML page delivered over the network without requiring user interaction beyond viewing a webpage. By writing data beyond allocated buffer boundaries, an attacker can overwrite adjacent memory and potentially achieve arbitrary code execution outside the sandbox, compromising system security. The vulnerability is fixed in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Disclosed in Chrome 152.0.7977.65 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65