Executive brief
Google Chrome, a widely used web browser, contains a memory safety vulnerability in its ANGLE graphics component that affects Windows systems. An attacker can exploit this through a crafted web page to execute arbitrary code outside the browser's security sandbox, potentially compromising the entire system and accessing sensitive user data.
Technical details
A use-after-free vulnerability exists in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome on Windows prior to version 153.0.8010.36. The vulnerability allows a remote attacker to craft a malicious HTML page that, when visited, exploits the memory safety flaw to execute arbitrary code with privileges outside the browser sandbox. The attack requires only that a user visit a malicious webpage and does not require authentication or prior system access. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36 on Windows
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released