Description
Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write in the ANGLE graphics engine of Google Chrome can be triggered by a maliciously crafted HTML page. If the attacker has already managed to compromise the renderer process, the flaw can be used to escape Chromium’s sandbox and execute arbitrary code on the machine. The weakness is classified as CWE‑787.

Affected Systems

All users of Google Chrome versions prior to 151.0.7922.72 are affected, regardless of operating system, when browsing the web or opening local files that include the crafted HTML content.

Risk and Exploitability

The CVSS score of 9.6 denotes critical severity, yet the EPSS score of less than 1% indicates a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a user visiting a malicious website or opening a locally stored HTML file that includes the exploit. The attacker must first gain a foothold in the renderer process, after which the out‑of‑bounds write can be used to escape the sandbox and elevate privileges.

Generated by OpenCVE AI on August 3, 2026 at 12:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.72 or newer to apply the ANGLE out‑of‑bounds write fix
  • Enable Chrome’s automatic update feature to ensure future security updates are applied promptly
  • If an immediate update cannot be performed, run Chrome within a confined environment such as a container or virtual machine to contain any potential sandbox escape

Generated by OpenCVE AI on August 3, 2026 at 12:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in ANGLE Allowing Sandbox Escape in Google Chrome chromium-browser: chromium-browser: Out of bounds write in ANGLE
References
Metrics threat_severity

None

threat_severity

Important


Fri, 31 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in ANGLE Allowing Sandbox Escape in Google Chrome

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T17:37:55.497Z

Reserved: 2026-07-27T23:34:20.153Z

Link: CVE-2026-17675

cve-icon Vulnrichment

Updated: 2026-07-30T16:34:18.235Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:29.670

Modified: 2026-08-03T12:17:16.540

Link: CVE-2026-17675

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-30T00:18:49Z

Links: CVE-2026-17675 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:45:03Z

Weaknesses