Junglewise Threat Intelligence

CVE-2026-79131: Google Chrome out of bounds write in ANGLE

CVE-2026-79131 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics rendering engine contained a buffer overflow vulnerability that allowed attackers to execute arbitrary code beyond Chrome's security sandbox. A user opening a malicious webpage could enable an attacker to break out of Chrome's isolation protections and potentially compromise the entire system.

Technical details

An out-of-bounds write vulnerability in ANGLE (a Direct3D abstraction layer used for graphics rendering) allowed remote code execution outside the browser sandbox. The vulnerability could be triggered via a crafted HTML page without requiring user interaction beyond visiting the page. The flaw was patched in Chrome 152.0.7977.65 (released August 25, 2026). The vulnerability is classified as High severity by Chromium but carries a CVSS 9.6 score due to its sandbox escape capability, enabling arbitrary code execution with network attack vector.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Chrome 152.0.7977.65 released with fix
  • 2026-06-12: other: Vulnerability reported to Google

References

Related threats