Executive brief
Google Chrome's ANGLE graphics library contains a use-after-free vulnerability that allows remote attackers to execute arbitrary code with elevated privileges outside the browser sandbox via a specially crafted HTML page. This could enable attackers to fully compromise affected systems and access sensitive data without the normal browser sandbox protections.
Technical details
A use-after-free vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), Chrome's graphics library, in versions prior to 152.0.7977.65. The vulnerability can be triggered by a remote attacker via a crafted HTML page without user interaction beyond visiting the page. Successful exploitation allows code execution outside the sandbox boundary, giving attackers full system-level access. The vulnerability is network-reachable and affects all desktop platforms (Windows, Mac, Linux). A patch is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Chrome 152 stable release with fix
- 2026-08-25: patched: Chrome 152.0.7977.65 contains fix