Executive brief
Google Chrome is a widely used web browser that executes HTML pages and web content. An out of bounds write vulnerability in the ANGLE graphics library allows a remote attacker to execute malicious code outside the browser sandbox by crafting a specially designed HTML page, potentially compromising the entire system and exposing user data.
Technical details
The vulnerability is an out of bounds write in ANGLE (Almost Native Graphics Layer Engine), Chrome's graphics abstraction layer. The flaw resides in memory bounds checking for graphics operations, which can be triggered via a crafted HTML page. The attack requires only network access and user interaction (loading a malicious webpage); no authentication is needed. Successful exploitation allows arbitrary code execution outside the browser's sandbox security boundary, giving an attacker elevated system privileges. The vulnerability is fixed in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65