Executive brief
Google Chrome is a widely used web browser that runs web pages and applications. An out of bounds write vulnerability in ANGLE (the graphics rendering engine) allows a remote attacker to execute arbitrary code inside the browser's sandbox by tricking a user into viewing a specially crafted HTML page. This could lead to code execution, data theft, or malware installation.
Technical details
An out of bounds write vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction component in Google Chrome on Windows prior to version 152.0.7977.65. The vulnerability allows remote code execution within the sandbox via a crafted HTML page; no user interaction beyond visiting the malicious page is required. The attacker can achieve arbitrary code execution within the restricted sandbox environment, which may allow further compromise depending on additional sandbox escape vulnerabilities. The patch is available in Chrome 152.0.7977.65 and later for Windows and Mac platforms.
Affected products
- Google Chrome prior to 152.0.7977.65 on Windows
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 and later