Description
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The ANGLE bug in the graphics abstraction layer used by Google Chrome is a type confusion (CWE-843) vulnerability. By delivering a specially crafted HTML page, a remote attacker can induce the browser to which may allow sandbox escape. The CVSS score of 9.6 demonstrates the potential to compromise system integrity by executing code beyond the restricted privileges of the browser process.

Affected Systems

Google Chrome browsers before version 150.0.7871.47 are affected. Only Google Chrome receives patches; no other vendors or products are known to be impacted.

Risk and Exploitability

A remote attacker can trigger the flaw by serving a specially crafted HTML page. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The CVSS score of 9.6 reflects a very high severity, such that successful exploitation would grant sandbox escape and privilege escalation beyond the browser process KEV catalog.

Generated by OpenCVE AI on July 17, 2026 at 14:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer.
  • If an upgrade cannot be performed, disable inline scripting to limit execution of potentially malicious HTML.
  • Implement web filtering or firewall rules to block known malicious HTML content that may trigger the ANGLE vulnerability.

Generated by OpenCVE AI on July 17, 2026 at 14:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in ANGLE Allows Potential Sandbox Escape from Malicious HTML

Thu, 16 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in ANGLE Allows Potential Sandbox Escape from Malicious HTML

Tue, 14 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion Enables Sandbox Escape in Chrome

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion Enables Sandbox Escape in Chrome

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Type Confusion in ANGLE Enables Sandbox Escape in Google Chrome

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in ANGLE Enables Sandbox Escape in Google Chrome

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Type Confusion in Chrome ANGLE

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Type Confusion in Chrome ANGLE

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE Type Confusion in Google Chrome

Wed, 08 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE Type Confusion in Google Chrome

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Type Confusion Enables Sandbox Escape in Chrome via Crafted HTML

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Type Confusion Enables Sandbox Escape in Chrome via Crafted HTML

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE Type Confusion in Chrome

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via ANGLE Type Confusion in Chrome

Sat, 04 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion Leads to Potential Sandbox Escape in Chrome

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion Leads to Potential Sandbox Escape in Chrome

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Type Confusion Enables Sandbox Escape via Crafted HTML

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Type Confusion Enables Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion in Chrome Enables Potential Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion in Chrome Enables Potential Sandbox Escape via Crafted HTML

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Type‑Confusion Bug in ANGLE Enables Potential Sandbox Escape via Crafted HTML

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Type‑Confusion Bug in ANGLE Enables Potential Sandbox Escape via Crafted HTML

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion Leading to Sandbox Escape in Google Chrome

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title ANGLE Type Confusion Leading to Sandbox Escape in Google Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:04:49.101Z

Reserved: 2026-06-29T23:03:41.575Z

Link: CVE-2026-13883

cve-icon Vulnrichment

Updated: 2026-07-01T15:04:00.360Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:45:06Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')