Description
Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome’s ANGLE component contains an out‑of‑bounds read that a crafted HTML page can trigger, allowing memory that may contain cross‑origin data to be read. The vulnerability exploits a flaw in memory bounds handling, as categorized by CWE‑125, and can lead to confidential information disclosure without affecting integrity or availability directly.

Affected Systems

The flaw exists in Google Chrome running on Windows, affecting any version prior to 150.0.7871.46. Users of older browsers are susceptible when visiting malicious web pages that leverage ANGLE rendering.

Risk and Exploitability

The EPSS score of < 1 % indicates a low exploitation probability, reflecting the rarity of observed attacks. The vulnerability is not listed in CISA KEV. Chromium security severity is medium with a CVSS score of 6.5. Attackers could exploit the flaw by luring users to a crafted HTML page that uses ANGLE rendering, without needing extra privileges or authentication. Although the CVSS score denotes a moderate impact, the low EPSS and absence from KEV suggest that widespread exploitation is unlikely, but the attack remains feasible if an attacker can deliver the malicious page.

Generated by OpenCVE AI on July 17, 2026 at 11:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 150.0.7871.46 or newer as promoted by Google releases
  • If unable to update immediately, consider restricting access to sites that may serve malicious content via web filtering or user training to avoid visiting untrusted ANGLE usage until a patch is applied
  • Temporarily disable the ANGLE renderer by launching Chrome with the --disable-angle flag until a patch is available

Generated by OpenCVE AI on July 17, 2026 at 11:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Out‑of‑Bounds Read Enables Cross‑Origin Data Leakage

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out of bounds read in ANGLE causes cross‑origin data leakage in Chrome for Windows

Tue, 14 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out of bounds read in ANGLE causes cross‑origin data leakage in Chrome for Windows

Mon, 13 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out-of-Bounds Read Enables Cross‑Origin Data Leakage in Google Chrome

Sun, 12 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out-of-Bounds Read Enables Cross‑Origin Data Leakage in Google Chrome

Sun, 12 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑bounds Read Allows Cross‑Origin Data Leakage

Sat, 11 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑bounds Read Allows Cross‑Origin Data Leakage

Fri, 10 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chromium ANGLE out‑of‑bounds read may leak cross‑origin data

Wed, 08 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Chromium ANGLE out‑of‑bounds read may leak cross‑origin data

Tue, 07 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Out‑of‑Bounds Read in Chrome's ANGLE on Windows

Tue, 07 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leakage via Out‑of‑Bounds Read in Chrome's ANGLE on Windows

Mon, 06 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE Allows Cross‑Origin Data Leakage

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE Allows Cross‑Origin Data Leakage

Sun, 05 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via ANGLE Out‑of‑Bounds Read in Google Chrome

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via ANGLE Out‑of‑Bounds Read in Google Chrome

Sat, 04 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in ANGLE Enables Cross-Origin Data Leak in Chrome

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in ANGLE Enables Cross-Origin Data Leak in Chrome

Fri, 03 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title ANGLE out-of-bounds read leads to remote data leakage in Chrome on Windows

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title ANGLE out-of-bounds read leads to remote data leakage in Chrome on Windows

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Cross‑Origin Data Leakage

Thu, 02 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Cross‑Origin Data Leakage

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T16:43:45.514Z

Reserved: 2026-07-01T21:37:24.280Z

Link: CVE-2026-14384

cve-icon Vulnrichment

Updated: 2026-07-02T16:42:27.483Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T12:00:04Z

Weaknesses