Description
Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-18
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a buffer overflow in ANGLE, a graphics abstraction layer used by Chrome on Android. An attacker who has already compromised the renderer process can feed a specially crafted HTML page to trigger an out‑of‑bounds write that bypasses the sandbox. This vulnerability can lead to arbitrary code execution in a process outside Chrome’s sandbox.

Affected Systems

Google Chrome for Android versions earlier than 151.0.7922.169 are affected. Any device running these releases and that renders untrusted web pages is exposed to the risk.

Risk and Exploitability

Chromium rates the vulnerability as high and labels it a buffer overflow (CWE‑122). The EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating no confirmed exploitation at this time. The attack requires an initial compromise of the renderer process—potentially via a prior flaw or a malicious extension—after which arbitrary code can be executed with privileges beyond the sandbox. The risk remains significant for users that load suspicious web content on affected Chrome Android installations.

Generated by OpenCVE AI on August 18, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome on Android to version 151.0.7922.169 or later to apply the ANGLE overflow fix.
  • Until the update is installed, avoid loading suspicious HTML pages and disable or remove any extensions that operate in the renderer process, as they could provide the prerequisite for compromise.
  • Monitor for anomalous renderer crashes or unexpected behaviors and apply any subsequent security patches as soon as they become available.

Generated by OpenCVE AI on August 18, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in ANGLE Allows Arbitrary Code Execution via Malicious HTML on Android Chrome
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 18 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-18T20:31:27.388Z

Reserved: 2026-08-18T19:45:04.495Z

Link: CVE-2026-76046

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:18:28.750

Modified: 2026-08-18T21:18:28.750

Link: CVE-2026-76046

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T21:45:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow