Junglewise Threat Intelligence

CVE-2026-87654: Google Chrome buffer overflow in ANGLE on Windows

CVE-2026-87654 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Executive brief

Google Chrome contains a buffer overflow vulnerability in the ANGLE graphics library that allows attackers to execute arbitrary code outside the browser's security sandbox. An attacker can exploit this by sending a specially crafted web page to a user; if visited, the vulnerability enables complete system compromise including data theft and malware installation. This affects Chrome on Windows prior to version 153.0.8010.36.

Technical details

A buffer overflow vulnerability exists in ANGLE (Almost Native Graphics Layer Engine), a graphics abstraction library used by Chrome, prior to version 153.0.8010.36 on Windows. The vulnerability allows a remote attacker to execute arbitrary code outside the Chrome sandbox via a crafted HTML page, indicating the attacker can break out of the browser's security boundary. The attack vector is network-based and requires no user authentication beyond visiting a malicious webpage. The vulnerability has been classified as High severity by the Chromium project and patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-08: disclosed: Patched in Chrome 153.0.8010.36
  • 2026-09-09: other: NVD published advisory

References

Related threats