Executive brief
Google Chrome's ANGLE graphics component (used to render web graphics on all platforms) has an improper input validation flaw that allows remote code execution outside the browser's security sandbox. A user visiting a malicious website could be compromised, leading to potential theft of browser data, passwords, and credentials or complete system compromise depending on user privileges.
Technical details
This vulnerability is an improper input validation issue in ANGLE, Google Chrome's abstraction layer for graphics APIs (used to accelerate WebGL and Canvas rendering). The flaw allows a remote attacker to craft a malicious HTML page that, when visited by a user, triggers arbitrary code execution outside the browser sandbox. The attack vector is network-based and requires user interaction (visiting a malicious page). No authentication is required. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026, and Google assigned it High severity (reported CVSS 8.8).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65