Description
Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in Chrome’s ANGLE graphics engine allows a remote attacker to potentially escape the browser sandbox by delivering a crafted HTML page. The CVE description belongs to CWE-693. The description indicates that escaping the sandbox could enable code execution beyond browser boundaries; however, the extent of impact on confidentiality, integrity or availability is not explicitly confirmed and the escape is described as a potential risk rather than a proven exploitation path.

Affected Systems

The flaw is present in all installations of Google Chrome that use the ANGLE implementation before version 150.0.7871.47. Based on the description, it is inferred that this includes current releases for Windows, macOS, Linux, and ChromeOS, unless the browser is built without ANGLE. The vulnerability does not depend on the operating system or device type.

Risk and Exploitability

The CVSS score of 9.6 indicates a high severity, while the EPSS score of less than 1% and absence from the CISA KEV list suggest a low chance of exploitation presently. The attack surface consists of a remote malicious web page that can be hosted by an adversary without requiring local privileges. This remote trigger makes the flaw attractive once discovered, warranting prompt patching and mitigation of untrusted web content.

Generated by OpenCVE AI on July 16, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all Chrome installations to version 150.0.7871.47 or newer to patch the ANGLE implementation flaw.
  • Enable Chrome’s automatic update mechanism to ensure timely receipt of security patches.
  • If update deployment must be delayed, restrict the browser to trusted content by using web‑filtering solutions or browser policies that block potentially malicious HTML pages until the update is applied.

Generated by OpenCVE AI on July 16, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape via Crafted HTML Page

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape via Crafted HTML Page

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Wed, 08 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title ANGLE Graphics Engine Enables sandbox escape using crafted HTML page

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title ANGLE Graphics Engine Enables sandbox escape using crafted HTML page

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape Vulnerability via Crafted HTML Page

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape Vulnerability via Crafted HTML Page

Sat, 04 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title ANGLE Sandbox Escape via Crafted HTML Page in Google Chrome

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title ANGLE Sandbox Escape via Crafted HTML Page in Google Chrome

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title ANGLE Implementation Flaw Enables Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title ANGLE Implementation Flaw Enables Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via Inadequate ANGLE Implementation in Chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via Inadequate ANGLE Implementation in Chrome

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via ANGLE in Google Chrome
Weaknesses CWE-264
CWE-272

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via ANGLE in Google Chrome
Weaknesses CWE-264
CWE-272

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:33:44.797Z

Reserved: 2026-06-29T23:03:35.629Z

Link: CVE-2026-13859

cve-icon Vulnrichment

Updated: 2026-07-01T14:33:32.752Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T00:15:06Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure