Junglewise Threat Intelligence

CVE-2026-79189: Google Chrome out of bounds write in ANGLE

CVE-2026-79189 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics library contains an out of bounds write vulnerability that allows attackers to bypass Chrome's security sandbox through a malicious webpage. An attacker could potentially execute arbitrary code with elevated privileges, compromising the integrity and security of affected systems.

Technical details

This vulnerability is an out of bounds write in ANGLE (the graphics abstraction layer used by Chrome). The flaw allows a remote attacker to write data beyond the bounds of allocated memory when processing crafted HTML content. The attack requires no user interaction beyond visiting a malicious webpage—the vulnerability can be triggered via the network through a crafted HTML page. If successfully exploited, an attacker can escape the Chrome sandbox and potentially achieve arbitrary code execution on the host system. The vulnerability was patched in Chrome 152.0.7977.65 released on 2026-08-25.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats