Executive brief
Google Chrome's ANGLE graphics rendering library contains an input validation flaw that allows attackers to escape the browser sandbox and execute arbitrary code. An attacker can exploit this vulnerability by hosting a malicious webpage, which would compromise the entire system if visited by a user, potentially leading to data theft, malware installation, or full device takeover.
Technical details
The vulnerability is an improper input validation flaw in the ANGLE (Almost Native Graphics Layer Engine) component of Google Chrome. It allows a remote attacker to bypass sandbox protections and execute arbitrary code with elevated privileges. The attack vector is network-based, requiring only that a user visits a crafted HTML page in a vulnerable Chrome version (prior to 153.0.8010.47). No user authentication or additional interaction beyond page visitation is required. An attacker can achieve arbitrary code execution outside the browser sandbox, giving them full system access. The vulnerability has been patched in Chrome version 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed: Public disclosure of CVE-2026-91738