Description
Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-08-06
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds write occurs in ANGLE, a graphics library used by Google Chrome, when processing a crafted HTML page on Android. This flaw permits an attacker to escape the browser sandbox, potentially allowing the execution of arbitrary native code on the device. The weakness is a classic out‑of‑bounds write, classified as CWE‑787, and the Chromium team rates its severity as Critical. The impact therefore spans confidentiality, integrity, and potentially availability if the attacker can modify or disable process resources.

Affected Systems

Google Chrome running on Android devices prior to version 151.0.7922.109 is affected. This includes any user who installed that stable channel build or an earlier one on an Android device. The vulnerability resides in the ANGLE component of Chrome’s rendering engine.

Risk and Exploitability

The flaw is a remote code execution vulnerability that can be triggered by a malicious web page rendered by Chrome on Android. Because it requires the victim to interact with a crafted page, the attack vector is remote with user interaction. The EPSS score of <1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, but the CVSS score of 9.6 demonstrates that it is considered critical, suggesting a high potential for exploitation if the flaw is in a frequently used component. Without an available exploit yet, the risk remains theoretical but significant for users on affected Chrome releases.

Generated by OpenCVE AI on August 7, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to the latest stable release (151.0.7922.109 or newer).
  • Avoid opening untrusted or suspicious web pages that could contain malicious HTML content.
  • Implement enterprise device management or policy settings to restrict rendering of untrusted content and enforce the Chrome sandbox.

Generated by OpenCVE AI on August 7, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4728-1 chromium security update
Debian DSA Debian DSA DSA-6422-1 chromium security update
History

Fri, 14 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in ANGLE Enables Sandbox Escape via Crafted HTML chromium-browser: ANGLE: Sandbox escape via out-of-bounds write in Google Chrome on Android
References
Metrics threat_severity

None

threat_severity

Important


Fri, 07 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in ANGLE Enables Sandbox Escape via Crafted HTML

Fri, 07 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-07T12:54:38.303Z

Reserved: 2026-08-06T16:51:49.315Z

Link: CVE-2026-19157

cve-icon Vulnrichment

Updated: 2026-08-07T00:20:56.530Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-06T22:16:58.010

Modified: 2026-08-07T15:06:52.130

Link: CVE-2026-19157

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-06T20:33:40Z

Links: CVE-2026-19157 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T15:15:04Z

Weaknesses