Junglewise Threat Intelligence

CVE-2026-79130: Google Chrome buffer overflow in ANGLE

CVE-2026-79130 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics library contains a buffer overflow vulnerability that can be exploited by a remote attacker through a malicious HTML page. An attacker can use this flaw to break out of Chrome's security sandbox and execute arbitrary code with full system privileges, potentially compromising user data, installing malware, or taking complete control of the affected computer.

Technical details

A buffer overflow vulnerability exists in ANGLE, Google Chrome's graphics abstraction layer. The vulnerability is triggered by a crafted HTML page served over the network, requiring only that a user visits a malicious website—no prior authentication or user interaction beyond normal browsing is needed. The flaw allows an attacker to escape Chrome's sandbox, executing arbitrary code at the system level. Google patched this vulnerability in Chrome 152.0.7977.65, released on August 25, 2026. Chromium project classified this as a High-severity issue with a CVSS score of 9.6.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-06-14: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats