Executive brief
Google Chrome's ANGLE rendering component contains an out of bounds memory read vulnerability on Windows that allows an attacker to read memory outside the browser's sandbox protections. A remote attacker can exploit this vulnerability through a crafted HTML page to potentially access sensitive data or gain information useful for further attacks.
Technical details
This is an out of bounds read vulnerability in the ANGLE (Almost Native Graphics Layer Engine) graphics component of Google Chrome on Windows. The vulnerability allows a remote attacker to read memory outside the sandbox via a specially crafted HTML page. No user interaction beyond visiting a malicious webpage is required. The vulnerability was patched in Chrome 153.0.8010.36 and later. The Chromium project assigned this a Low severity rating internally, though the CVSS score is 4.7 (medium).
Affected products
- Google Chrome prior to 153.0.8010.36 on Windows
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released