Junglewise Threat Intelligence

CVE-2026-87586: Google Chrome out of bounds read in ANGLE

CVE-2026-87586 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's ANGLE graphics engine contains an out of bounds memory read vulnerability that allows an attacker to extract sensitive data from memory by visiting a malicious webpage. This could expose user data that should be protected by Chrome's security sandbox, potentially compromising user privacy or enabling further attacks.

Technical details

The vulnerability is an out of bounds read in ANGLE (A Nice Angle Library), a graphics abstraction layer used by Chrome. The flaw allows an attacker to craft a malicious HTML page that triggers a memory read beyond allocated buffer boundaries. The attack vector is network-based (requires a user to visit a malicious website) with no authentication or special user interaction beyond loading the page. An attacker can read memory outside the Chrome sandbox protection, potentially accessing sensitive process data. The fix is available in Chrome 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats