Description
Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free condition exists in the ANGLE graphics component of Google Chrome on Windows when the browser version is older than 151.0.7922.72. The flaw can be triggered by a crafted HTML page served to the victim and may enable a sandbox escape, thereby allowing an attacker to lift the browser’s security restrictions and execute code with elevated privileges. The weakness is listed as CWE‑416, indicating a classic memory‑management problem. The vulnerability is rated Medium by Chromium security, and it specifically targets client‑side rendering of web content.

Affected Systems

The impact is limited to Microsoft Windows systems running Google Chrome v151.0.7922.71 or earlier. Only the stable channel of Chrome is mentioned in the advisories, but any affected build that incorporates the vulnerable ANGLE code falls under this scope. Users of experimental or beta builds that match these version constraints are also exposed.

Risk and Exploitability

The exploit probability is very low, with an EPSS score of less than 1%, and the flaw is not listed in the CISA KEV catalog, indicating limited known or documented exploitation. The attack vector requires a remote attacker to supply a malicious HTML page that the victim must load, usually by tricking the user into visiting a compromised site or link. Once the page loads, the use‑after‑free can trigger a sandbox escape if the attacker supplies sufficient crafted content. The CVSS score of 7.1 indicates medium severity, and the nature of the flaw suggests that a successful exploit could result in significant impact on the user’s system.

Generated by OpenCVE AI on August 2, 2026 at 06:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.72 or later using the built‑in updater or by downloading the latest stable installer from the official site.
  • Confirm that Chrome’s auto‑update feature is enabled so that future security releases are applied automatically.
  • If an immediate upgrade is not possible, disable WebGL or GPU acceleration via Chrome flags (e.g., chrome://flags) to reduce exposure while the patch is pending.

Generated by OpenCVE AI on August 2, 2026 at 06:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Use‑After‑Free Allows Sandbox Escape chromium-browser: chromium-browser: Use after free in ANGLE
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 31 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome ANGLE Use‑After‑Free Allows Sandbox Escape

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T14:04:45.270Z

Reserved: 2026-07-27T23:34:54.735Z

Link: CVE-2026-17811

cve-icon Vulnrichment

Updated: 2026-07-31T14:04:41.966Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:44.603

Modified: 2026-08-03T15:00:48.917

Link: CVE-2026-17811

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:28Z

Links: CVE-2026-17811 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:45:03Z

Weaknesses