Executive brief
Google Chrome's ANGLE graphics library on Android contains a buffer overflow vulnerability that allows remote attackers to execute arbitrary code outside the browser sandbox by viewing a specially crafted web page. This could lead to complete compromise of the Android device, including access to personal data and system functions.
Technical details
A buffer overflow exists in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction library used by Chrome on Android, affecting versions prior to 152.0.7977.65. The vulnerability can be triggered remotely via a crafted HTML page without requiring user authentication or special privileges beyond visiting a malicious website. An attacker can achieve arbitrary code execution outside the sandbox boundary, which normally restricts Chrome's access to system resources. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed: Chrome 152.0.7977.65 released with fix
- 2026-06-30: other: Vulnerability reported to Google