Description
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

This vulnerability is an out of bounds write in the ANGLE graphics layer of Google Chrome that can be triggered by a maliciously crafted HTML page. The flaw allows a remote attacker to break out of the renderer process sandbox and execute arbitrary code on the host system. The weakness is a classic buffer overrun listed as CWE-787, and the potential for full system compromise exists if the user visits the malicious page.

Affected Systems

The issue affects all versions of Google Chrome released before build 152.0.7977.65. Therefore any user running Chrome 151.x or earlier on Windows, macOS, or Linux is vulnerable. The problem is present in the stable channel and does not affect the Canary or Beta channels if they are already updated. Users of the new release 152.0.7977.65 and later are not impacted.

Risk and Exploitability

Although the official Chromium security severity is Medium, the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting that no widespread exploitation campaigns have been observed yet. The CVSS score of 8.8 reflects the high severity of the remote code execution flaw. However, the remote code execution nature of the flaw means that an attacker who can serve a crafted HTML page is likely able to compromise the victim's machine. The exploit would require the user to visit the malicious page, so social or phishing vectors remain the primary attack medium until proof of penetration tools appear.

Generated by OpenCVE AI on August 26, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer
  • Use enterprise policy to enforce automatic updates for all Chrome installations
  • Configure Chrome to use the sandbox and protect mode for untrusted web content

Generated by OpenCVE AI on August 26, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Out of Bounds Write in ANGLE Allows Remote Code Execution

Wed, 26 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Out of Bounds Write in ANGLE Allows Remote Code Execution

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:02.323Z

Reserved: 2026-08-25T06:10:02.715Z

Link: CVE-2026-79127

cve-icon Vulnrichment

Updated: 2026-08-26T14:27:25.907Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:07.873

Modified: 2026-08-27T13:07:19.270

Link: CVE-2026-79127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T18:30:02Z

Weaknesses