


Perceptive Security
SOC/SIEM Consultancy

Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to p…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 16:04:07
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17676 is a high-severity vulnerability in Google Chrome for Android affecting versions prior to 151.0.7922.72. The flaw resides in ANGLE (Almost Native Graphics Layer Engine), a graphics abstraction layer used by Chrome. An attacker who has already compromised the renderer process can exploit an inappropriate implementation in ANGLE to perform a sandbox escape. The attack vector requires the victim to visit a specially crafted HTML page. This represents a significant escalation-of-privilege risk, as it allows breaking out of the Chrome sandbox, potentially leading to broader system compromise. Google has assigned this a 'High' severity rating under Chromium's security severity scale. A fix was delivered in the stable channel update for Chrome 151.0.7922.72 on Android.
Technical details
Mitigation steps:
Affected products:
Google Chrome for Android (prior to 151.0.7922.72)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17676
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/513920298
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
