Description
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in ANGLE used by Google Chrome on Windows platforms prior to version 152.0.7977.65, a flaw identified as CWE‑787. A maliciously crafted HTML page can cause memory to be read or overwritten beyond intended bounds, potentially breaking sandbox isolation and enabling arbitrary code execution inside the browser. Chromium security reviewers have classified this flaw as High severity.

Affected Systems

Affected systems are installations of Google Chrome running on Windows with versions older than 152.0.7977.65. The flaw resides in the ANGLE rendering engine that processes HTML content delivered to all Windows users of Chrome.

Risk and Exploitability

The CVSS score is 8.8, indicating a high impact. The EPSS score is <1%, suggesting a low overall exploitation probability at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The most realistic attack vector involves a remote attacker delivering or embedding a specially crafted HTML page via a website or local file that is opened by the user in an affected Chrome instance. If leveraged successfully, the out‑of‑bounds write can escape the rendering sandbox, giving the attacker full control of the browser process and the possibility of broader system compromise.

Generated by OpenCVE AI on August 26, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or newer to apply the fix for the ANGLE out‑of‑bounds write.
  • If an update cannot be applied immediately, restrict the browser from loading untrusted content by using Chrome’s privacy settings or by blocking external HTML files from unknown sources.
  • Keep the Windows operating system and all other installed software up to date to reduce the overall attack surface.

Generated by OpenCVE AI on August 26, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Wed, 26 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in ANGLE Enables Remote Code Execution via Crafted HTML Page

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in ANGLE Enables Remote Code Execution via Crafted HTML Page

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:36.924Z

Reserved: 2026-08-25T06:08:15.528Z

Link: CVE-2026-79048

cve-icon Vulnrichment

Updated: 2026-08-26T15:25:28.347Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:00.583

Modified: 2026-08-27T04:17:13.817

Link: CVE-2026-79048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T19:30:05Z

Weaknesses