Description
Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper implementation of the ANGLE graphics engine in Google Chrome allows an attacker who serves a specially crafted HTML page to potentially escape the browser sandbox. The flaw is classified as CWE-693. While the official description indicates the possibility of sandbox escape, it does not confirm that the vulnerability has been successfully exploited in the wild, so the exact consequences for confidentiality, integrity, or availability remain indeterminate but could be severe if the escape is achieved.

Affected Systems

The flaw affects all Google Chrome installations that use ANGLE before version 150.0.7871.47, which includes the majority of current releases for Windows, macOS, Linux, and ChromeOS. The statement does not specify any operating‑system dependence, and there is no mention of Chrome builds that omit ANGLE, so it is inferred that any build that includes ANGLE is vulnerable.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical level of severity. The EPSS score of less than 1 % suggests a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote; a malicious web page accessed by a user could trigger the exploit. Because the flaw is a sandbox escape, successful exploitation would allow code to run outside the browser’s sandbox, potentially affecting the entire host system.

Generated by OpenCVE AI on August 3, 2026 at 06:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.47 or later to apply the ANGLE fix.
  • Activate Chrome’s automatic update mechanism to receive security patches promptly.
  • If an immediate update is not possible, apply a group‑policy or extension that blocks navigation to untrusted or suspicious web content, or enable Chrome’s Safe Browsing controls to reduce the risk of the crafted page being loaded.

Generated by OpenCVE AI on August 3, 2026 at 06:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape Vulnerability

Wed, 29 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape Vulnerability

Sun, 26 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in Chrome ANGLE Engine

Wed, 22 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in Chrome ANGLE Engine

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape via Crafted HTML Page

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape via Crafted HTML Page

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Wed, 08 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE in Chrome

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title ANGLE Graphics Engine Enables sandbox escape using crafted HTML page

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title ANGLE Graphics Engine Enables sandbox escape using crafted HTML page

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape Vulnerability via Crafted HTML Page

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape Vulnerability via Crafted HTML Page

Sat, 04 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title ANGLE Sandbox Escape via Crafted HTML Page in Google Chrome

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title ANGLE Sandbox Escape via Crafted HTML Page in Google Chrome

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title ANGLE Implementation Flaw Enables Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title ANGLE Implementation Flaw Enables Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via Inadequate ANGLE Implementation in Chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via Inadequate ANGLE Implementation in Chrome

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via ANGLE in Google Chrome
Weaknesses CWE-264
CWE-272

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Potential Sandbox Escape via ANGLE in Google Chrome
Weaknesses CWE-264
CWE-272

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:33:44.797Z

Reserved: 2026-06-29T23:03:35.629Z

Link: CVE-2026-13859

cve-icon Vulnrichment

Updated: 2026-07-01T14:33:32.752Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T07:00:05Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure