Executive brief
Google Chrome is a web browser used by billions of people worldwide. An out of bounds write vulnerability in ANGLE (a graphics library) allows a remote attacker to potentially execute arbitrary code outside the browser's sandbox by tricking users into visiting a malicious webpage, potentially compromising the entire system.
Technical details
This vulnerability is an out of bounds write in ANGLE, the graphics rendering library used by Chrome. The vulnerability allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page, bypassing Chrome's sandbox protections. The attack requires no authentication or user interaction beyond visiting a malicious webpage. The vulnerability affects Chrome versions prior to 152.0.7977.65 and has been patched in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65