Junglewise Threat Intelligence

CVE-2026-79275: Google Chrome use-after-free in ANGLE

CVE-2026-79275 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics rendering library contains a use-after-free vulnerability that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this by tricking a user into visiting a specially crafted web page, bypassing Chrome's security boundaries and gaining full system access with the user's privileges.

Technical details

A use-after-free vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome versions prior to 152.0.7977.65. This occurs when memory is accessed after being freed, allowing an attacker to execute arbitrary code. The vulnerability is reachable via network through a crafted HTML page—no user interaction beyond visiting the page is required. An attacker can achieve arbitrary code execution outside the sandbox, potentially compromising the entire system. The vulnerability has been fixed in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats