


Perceptive Security
SOC/SIEM Consultancy

Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 20:07:35
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17675 is a high-severity out-of-bounds write vulnerability in ANGLE (Almost Native Graphics Layer Engine) within Google Chrome. The flaw affects versions prior to 151.0.7922.72 and allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox. Exploitation is achieved via a specially crafted HTML page. The vulnerability has been assigned a High severity rating by the Chromium security team. Google has addressed the issue in the stable channel update released in July 2026. ANGLE is a graphics abstraction layer used by Chrome to translate OpenGL ES calls to platform-native graphics APIs, making it a critical component. Sandbox escape vulnerabilities are particularly dangerous as they can allow attackers to break out of the browser's security containment and interact with the underlying operating system.
Technical details
Mitigation steps:
Affected products:
Google Chrome prior to 151.0.7922.72
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17675
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/513920258
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
