top of page
perceptive_background_267k.jpg

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a…

Published:

29 July 2026 at 22:00:00

Alert date:

30 July 2026 at 20:07:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17675 is a high-severity out-of-bounds write vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw affects versions prior to 151.0.7922.72 and allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. Exploitation is achieved via a specially crafted HTML page. The vulnerability has been assigned a High severity rating by the Chromium security team. Google has addressed the issue in the stable channel update released in July 2026. ANGLE is a graphics abstraction layer used by Chrome to translate OpenGL ES calls to platform-native graphics APIs, making it a critical component. Sandbox escape vulnerabilities are particularly dangerous as they can allow attackers to break out of the browser's security containment and interact with the underlying operating system.

Technical details

Mitigation steps:

Affected products:

Google Chrome prior to 151.0.7922.72

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page