Executive brief
Google Chrome is a web browser used by billions of users worldwide. A memory vulnerability in ANGLE (the graphics library) could allow an attacker to execute malicious code outside Chrome's sandbox protection by tricking a user into visiting a crafted website, potentially compromising the entire system.
Technical details
An out of bounds write vulnerability exists in ANGLE, the graphics abstraction layer in Google Chrome on Windows. The vulnerability allows remote code execution outside the sandbox via a specially crafted HTML page. The attack requires user interaction (visiting a malicious website) but no authentication. This vulnerability affects Chrome versions prior to 153.0.8010.36 on Windows and was patched in version 153.0.8010.36 released September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: disclosed: Chrome 153.0.8010.36 released with fix
- 2026-09-09: advisory: CVE-2026-87621 published