Description
Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read in the ANGLE graphics subsystem of Google Chrome allowed a remote attacker to read memory beyond intended bounds, exposing cross‑origin data. The flaw does not grant code execution but can reveal sensitive information stored in Chrome’s process memory, meeting the criteria for a high security severity rating from Chromium. The vulnerability is identified as a memory read error (CWE‑125).

Affected Systems

Versions of Google Chrome older than 150.0.7871.46 are affected. The vulnerability involves the ANGLE component, which is part of Chrome’s graphics stack (this is inferred from the description). All users running those versions are potentially exposed if they visit malicious web content.

Risk and Exploitability

The CVSS score of 6.5 places the vulnerability in the medium severity range, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in production. The vulnerability is not listed in CISA’s KEV catalog. According to the description, a remote attacker can exploit the flaw by hosting a crafted HTML page that a victim opens; no remote code execution or privilege escalation is possible, but confidentiality can be impacted through arbitrary data disclosure.

Generated by OpenCVE AI on July 22, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all installations of Google Chrome to at least version 150.0.7871.46 to include the ANGLE memory‑read fix.
  • Apply or enforce a same‑origin policy and content security policy that blocks cross‑origin requests that could exploit the out‑of‑bounds read until the patch is applied.
  • Configure Chrome Enterprise policies to enforce automatic update installation and to restrict loading of untrusted HTML content via web security controls.

Generated by OpenCVE AI on July 22, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑Bounds Read Enables Cross‑Origin Data Leakage via Crafted HTML

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑Bounds Read Enables Cross‑Origin Data Leakage via Crafted HTML

Tue, 14 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in ANGLE Allows Cross‑Origin Data Leakage in Chrome

Sun, 12 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in ANGLE Allows Cross‑Origin Data Leakage in Chrome

Sat, 11 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑Bounds Read Enables Cross‑Origin Data Leakage

Thu, 09 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑of‑Bounds Read Enables Cross‑Origin Data Leakage

Wed, 08 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Out‑Of‑Bounds Read in ANGLE Enables Cross‑Origin Data Leakage

Wed, 08 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Out‑Of‑Bounds Read in ANGLE Enables Cross‑Origin Data Leakage

Tue, 07 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Cross‑Origin Data Leakage

Mon, 06 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Cross‑Origin Data Leakage

Sun, 05 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Out‑of‑Bounds Read Leaks Cross‑Origin Data

Sun, 05 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Out‑of‑Bounds Read Leaks Cross‑Origin Data

Sun, 05 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title ANGLE out‑of‑bounds read allows cross‑origin data leakage in Google Chrome

Sat, 04 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title ANGLE out‑of‑bounds read allows cross‑origin data leakage in Google Chrome

Sat, 04 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Allows Remote Cross‑Origin Data Leakage

Fri, 03 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Allows Remote Cross‑Origin Data Leakage

Fri, 03 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE Allows Remote Cross‑Origin Data Leakage

Thu, 02 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in Chrome ANGLE Allows Remote Cross‑Origin Data Leakage

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Remote Cross‑Origin Data Leakage

Thu, 02 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in ANGLE Enables Remote Cross‑Origin Data Leakage

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T17:05:13.787Z

Reserved: 2026-07-01T21:37:27.503Z

Link: CVE-2026-14396

cve-icon Vulnrichment

Updated: 2026-07-02T16:36:23.441Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:15:02Z

Weaknesses