Description
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A type confusion flaw exists in the ANGLE graphics stack of Google Chrome before version 152.0.7977.65. The flaw can be triggered by an attacker who hosts a specially crafted HTML page and can lead to execution of arbitrary code outside the browser sandbox. The security severity is rated high, indicating that exploitation could grant the attacker significant privileges over the host system.

Affected Systems

Google Chrome browsers running any release older than 152.0.7977.65 are vulnerable. All users of these versions who view untrusted web pages are at risk.

Risk and Exploitability

The vulnerability is remotely exploitable via a crafted HTML page delivered over the network. The EPSS score of 0.00381 indicates a very low probability of exploitation, but the high severity, with a CVSS score of 9.6, suggests a substantial risk to affected users. No mitigations are available other than applying the official patch, so the potential impact remains significant until the update is deployed.

Generated by OpenCVE AI on August 26, 2026 at 21:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later.
  • Ensure that enterprise update mechanisms are enabled so the browser automatically receives the new release.
  • Temporarily disable GPU acceleration via Chrome policy or command line until the update is applied.

Generated by OpenCVE AI on August 26, 2026 at 21:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chromium ANGLE Type Confusion Allows Remote Code Execution

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chromium ANGLE Type Confusion Allows Remote Code Execution

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:06.405Z

Reserved: 2026-08-25T06:03:59.710Z

Link: CVE-2026-78904

cve-icon Vulnrichment

Updated: 2026-08-26T16:24:39.715Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:47.747

Modified: 2026-08-27T16:23:55.243

Link: CVE-2026-78904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:45:03Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')