Description
Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-21
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write has been discovered in ANGLE, the graphics abstraction layer used by Google Chrome. The flaw allows a remote attacker, after having compromised the browser’s renderer process, to potentially escape the renderer sandbox and gain higher privileges on the host system. The weakness is a classic buffer overrun, classified as CWE‑787.

Affected Systems

The vulnerability affects all versions of Google Chrome released before 150.0.7871.182. It is tied to the ANGLE component used throughout Chrome’s rendering pipeline. Users running any affected Chrome edition on desktop platforms (Windows, macOS, Linux) are at risk if an attacker can serve a malicious web page that triggers the overflow.

Risk and Exploitability

The CVSS score of 8.3 indicates a high severity, while the EPSS score of less than 1 % indicates a currently low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires that the attacker first gain control of the renderer process, or, by social engineering, trigger the out‑of‑bounds write with a crafted HTML page delivered through a compromised or malicious website.

Generated by OpenCVE AI on August 4, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.182 or later
  • Enable site isolation and enforce stricter sandboxing for renderer processes
  • Apply a strict content security policy to prevent untrusted content from triggering renderer compromises

Generated by OpenCVE AI on August 4, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Sun, 02 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in ANGLE Enables Potential Sandbox Escape

Sat, 01 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in ANGLE Enables Potential Sandbox Escape

Mon, 27 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Out-of-bounds write in ANGLE leads to sandbox escape in Chrome

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Out-of-bounds write in ANGLE leads to sandbox escape in Chrome
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-24T12:46:27.440Z

Reserved: 2026-07-20T22:23:04.847Z

Link: CVE-2026-16413

cve-icon Vulnrichment

Updated: 2026-07-24T12:46:19.787Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses