Description
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an inappropriate implementation in ANGLE within Google Chrome on Android prior to version 151.0.7922.72 that permits a remote attacker to escape the browser sandbox through a crafted HTML page. This flaw is classified as CWE‑501 and CWE‑693, indicating improper input handling and missing secure configuration. The description notes that sandbox escape is possible but does not explicitly state the outcome; based on typical implications of a sandbox escape, successful exploitation might enable the attacker to execute code with the same privileges as the web content or read device data.

Affected Systems

Devices running Google Chrome for Android with a browser build older than version 151.0.7922.72 are affected. The issue applies only to this browser and does not extend to other browsers or components.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity level, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild at present. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a malicious HTML page that a user visits or interacts with; this inference is drawn from the phrasing that a crafted HTML page can trigger the ANGLE bug. If sandbox escape is achieved, the attacker may gain privileges equivalent to the browser process, potentially compromising device security.

Generated by OpenCVE AI on August 2, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome on Android to version 151.0.7922.72 or later.
  • Restrict access to untrusted web content in Chrome through device or network policies, such as blocking specific URLs or enforcing safe browsing controls.
  • Deploy device management solutions that enforce automatic updates for Chrome and monitor installed versions to ensure timely patching.

Generated by OpenCVE AI on August 2, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in ANGLE
Weaknesses CWE-501
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

threat_severity

Important


Thu, 30 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T17:37:48.946Z

Reserved: 2026-07-27T23:34:20.683Z

Link: CVE-2026-17677

cve-icon Vulnrichment

Updated: 2026-07-30T16:14:50.401Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:29.883

Modified: 2026-08-03T12:16:42.443

Link: CVE-2026-17677

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-30T00:18:50Z

Links: CVE-2026-17677 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T07:30:03Z

Weaknesses
  • CWE-501

    Trust Boundary Violation

  • CWE-693

    Protection Mechanism Failure