Description
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the ANGLE component of Google Chrome in all releases before 150.0.7871.46. It results from insufficient validation of untrusted input and is classified as an input validation flaw (CWE‑20). A crafted HTML page can bypass normal input checks and enable a sandbox escape, potentially allowing code execution with the privileges of the host user.

Affected Systems

The flaw affects all installations of Google Chrome older than version 150.0.7871.46, regardless of operating system. It is unrelated to extensions or third‑party plugins.

Risk and Exploitability

The CVSS score of 9.6 indicates severe risk. The EPSS score of less than 1 % implies a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector requires a crafted HTML page, which could be delivered via an untrusted website. No public exploit is known at this time, so while the potential impact is high, the probability of current exploitation remains limited.

Generated by OpenCVE AI on July 21, 2026 at 13:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.46 or later and restart the browser
  • Enable automatic updates to receive future security patches
  • If upgrading is not immediately possible, avoid opening untrusted or suspicious HTML content

Generated by OpenCVE AI on July 21, 2026 at 13:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in ANGLE Leading to Sandbox Escape

Wed, 15 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in ANGLE Leading to Sandbox Escape

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in ANGLE Leading to Sandbox Escape

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in ANGLE Leading to Sandbox Escape

Sat, 11 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chromium ANGLE Sandbox Escape via Untrusted Input

Fri, 10 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chromium ANGLE Sandbox Escape via Untrusted Input

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Browser Sandbox Escape via Unvalidated ANGLE Input

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Browser Sandbox Escape via Unvalidated ANGLE Input

Wed, 08 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape via Untrusted Input

Tue, 07 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Sandbox Escape via Untrusted Input

Mon, 06 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title ANGLE Component Input Validation Leading to Sandbox Escape in Chrome

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title ANGLE Component Input Validation Leading to Sandbox Escape in Chrome

Sun, 05 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in Chrome's ANGLE Rendering Engine

Sun, 05 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape Vulnerability in Chrome's ANGLE Rendering Engine

Sat, 04 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input in ANGLE Enables Sandbox Escape in Google Chrome

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input in ANGLE Enables Sandbox Escape in Google Chrome

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title ANGLE Sandbox Escape via Untrusted Input in Google Chrome

Thu, 02 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title ANGLE Sandbox Escape via Untrusted Input in Google Chrome

Thu, 02 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in ANGLE Enabling Sandbox Escape

Thu, 02 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in ANGLE Enabling Sandbox Escape
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:33.186Z

Reserved: 2026-07-01T21:37:31.043Z

Link: CVE-2026-14411

cve-icon Vulnrichment

Updated: 2026-07-02T00:01:37.125Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation