Junglewise Threat Intelligence

CVE-2026-87602: Google Chrome out of bounds read in ANGLE on Windows

CVE-2026-87602 · Severity: medium · CVSS 4.7 · Published 2026-09-09

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's ANGLE rendering component contains an out of bounds memory read vulnerability on Windows that allows an attacker to read memory outside the browser's sandbox protections. A remote attacker can exploit this vulnerability through a crafted HTML page to potentially access sensitive data or gain information useful for further attacks.

Technical details

This is an out of bounds read vulnerability in the ANGLE (Almost Native Graphics Layer Engine) graphics component of Google Chrome on Windows. The vulnerability allows a remote attacker to read memory outside the sandbox via a specially crafted HTML page. No user interaction beyond visiting a malicious webpage is required. The vulnerability was patched in Chrome 153.0.8010.36 and later. The Chromium project assigned this a Low severity rating internally, though the CVSS score is 4.7 (medium).

Affected products

  • Google Chrome prior to 153.0.8010.36 on Windows

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats