Description
Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the ANGLE graphics stack used by Google Chrome on Windows before version 152.0.7977.65. A crafted HTML page can corrupt memory inside the sandbox process, potentially allowing an attacker to execute arbitrary code. The weakness is identified as CWE‑787 and is rated high severity by Chromium’s internal scoring.

Affected Systems

Google Chrome installations running on Windows that have not yet been updated to version 152.0.7977.65 or later are affected. The ANGLE component of these releases is the point of exploitation.

Risk and Exploitability

The EPSS score is less than 1%, indicating a low probability of exploitation in the wild, but the CVSS score of 8.8 classifies the vulnerability as high. The vulnerability is not listed in the CISA KEV catalog. A remote attacker could host or deliver a malicious webpage containing a crafted HTML document, which, when rendered by a vulnerable browser, could trigger the out‑of‑bounds write, corrupt sandbox memory, potentially escape the sandbox, and execute arbitrary code. The likely attack vector is the delivery of a crafted HTML page over the network to a user’s browser, inferred from the description. Despite the low EPSS, the high impact of arbitrary code execution warrants immediate remediation.

Generated by OpenCVE AI on August 26, 2026 at 19:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or later.
  • If a patch cannot be applied immediately, block or restrict the execution of untrusted web content until the vulnerability is fixed.
  • Enable the browser’s sandbox features and consider disabling ANGLE via command‑line flags as a temporary workaround until an official fix is released.

Generated by OpenCVE AI on August 26, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Wed, 26 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑Of‑Bounds Write Enabling Remote Code Execution in Chrome on Windows

Wed, 26 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title ANGLE Out‑Of‑Bounds Write Enabling Remote Code Execution in Chrome on Windows

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:57:38.404Z

Reserved: 2026-08-25T06:12:19.142Z

Link: CVE-2026-79240

cve-icon Vulnrichment

Updated: 2026-08-26T15:26:20.599Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:18.283

Modified: 2026-08-31T18:14:45.343

Link: CVE-2026-79240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T19:30:05Z

Weaknesses