Impact
The vulnerability is an out‑of‑bounds memory write in the ANGLE component of Google Chrome versions older than 152.0.7977.65. A specially crafted HTML page can trigger this write, allowing a remote attacker to write beyond allocated buffers and potentially execute arbitrary code outside the browser sandbox. The flaw stems from a lack of proper bounds checking in the ANGLE graphics layer, and it is classified as CWE‑787.
Affected Systems
Google Chrome is the affected product; any installation running a version earlier than 152.0.7977.65 is vulnerable. This includes the stable channel releases updated before the August 2026 patch published by Google. Users of older Chrome builds without that update remain exposed.
Risk and Exploitability
The CVSS score is 9.6, indicating a high severity, and the EPSS score is < 1%. The vulnerability is not in the CISA KEV catalog. The attack can be delivered by a remote user who composes a malicious web page and lures a victim into visiting it. Because the flaw can escape the sandbox, successful exploitation could lead to full system compromise. Administrators should treat this as a priority issue.
OpenCVE Enrichment
Debian DLA
Debian DSA