CVE-2026-87500
massSandbox escape via array index validation flaw in Google Chrome ANGLE
CVE-2026-87500 is an improper validation of an array index (CWE-129) in ANGLE, the graphics translation layer in Google Chrome that converts WebGL/OpenGL ES calls to the host GPU API, fixed in Chrome 153.0.8010.36. A remote attacker can trigger the flaw by convincing a user to open a crafted HTML page, with no privileges required and user interaction needed (per the CVSS vector AV:N/AC:L/PR:N/UI:R). Because the bug resides in the ANGLE/GPU component, successful exploitation could let the attacker execute arbitrary code outside Chrome's sandbox, granting broader access to the host than a typical renderer bug — consistent with the changed scope (S:C) in the CVSS vector and Chromium's High severity rating. All users of Google Chrome prior to 153.0.8010.36 are affected. There is currently no evidence of in-the-wild exploitation: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days.
What to do: Update Google Chrome to 153.0.8010.36 or later via the built-in auto-updater and verify the running build under Settings > About Chrome, relaunching the browser to ensure the patched version is loaded. Organizations managing Chrome via enterprise policies should confirm the updated build has rolled out to all managed endpoints; until patched, limiting exposure to untrusted web content reduces risk given the WebGL/graphics-adjacent nature of the flaw.
| Google Chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper validation of array index in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-129
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.