Description
Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write inside ANGLE, the graphics abstraction layer used by Chrome. A carefully crafted HTML page can push data beyond the intended buffer bounds, potentially allowing a remote attacker to execute code outside the browser sandbox. The attack could result in full system compromise if the sandbox is bypassed.

Affected Systems

Affected systems are Google Chrome desktop users running any version prior to 152.0.7977.65. This includes the stable channel releases available as of August 2026. The issue is disclosed by Google and referenced in the Chrome release notes and Chromium issue tracker.

Risk and Exploitability

The CVSS score of 9.6 indicates a critical severity. The EPSS score of <1% indicates a very low exploitation probability, but the lack of a CISA KEV listing does not reduce the risks: remote code execution through a crafted web page remains a serious threat. The expected attack vector is a malicious web page served to a user; the attacker must only get the user to load the page. Immediate patches are recommended due to this remote execution potential.

Generated by OpenCVE AI on August 26, 2026 at 19:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later, which contains the ANGLE out‑of‑bounds write fix.
  • If an update cannot be applied immediately, disable or restrict untrusted extensions and enforce Chrome’s sandboxed process model by ensuring the sandbox feature is turned on.
  • Monitor browser and system logs for evidence of sandbox escapes or anomalous executions, and maintain up‑to‑date antivirus definitions.

Generated by OpenCVE AI on August 26, 2026 at 19:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Out of Bounds Write in ANGLE Allows Arbitrary Code Execution via Crafted HTML Page

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Out of Bounds Write in ANGLE Allows Arbitrary Code Execution via Crafted HTML Page

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:35.360Z

Reserved: 2026-08-25T06:11:09.263Z

Link: CVE-2026-79189

cve-icon Vulnrichment

Updated: 2026-08-26T15:24:33.206Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:12.597

Modified: 2026-08-27T04:17:42.673

Link: CVE-2026-79189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T19:30:05Z

Weaknesses