Executive brief
Google Chrome's ANGLE graphics engine contains a use-after-free vulnerability affecting Android versions before 152.0.7977.65. A remote attacker can exploit this flaw by serving a crafted HTML page, potentially executing arbitrary code outside the sandbox and compromising the device with full browser-level privileges.
Technical details
This is a use-after-free vulnerability in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Chrome. The vulnerability allows remote code execution outside Chrome's sandbox when processing a maliciously crafted HTML page. The attack requires only network access and user interaction (visiting a malicious webpage); no authentication is required. Successful exploitation enables arbitrary code execution with the privileges of the Chrome process, potentially leading to complete system compromise. The vulnerability is patched in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65
- 2026-03-27: other: Reported to Google