CVE-2026-87586
PoC massOut-of-bounds read in Google Chrome's ANGLE graphics layer (CVE-2026-87586)
CVE-2026-87586 is an out-of-bounds read (CWE-125) in ANGLE, the graphics translation layer used by Google Chrome, affecting versions prior to 153.0.8010.36. It is triggered remotely via a crafted HTML page: an attacker who gets a user to open malicious web content can cause ANGLE to read memory beyond its intended bounds. A successful exploit allows the attacker to read memory outside the Chrome sandbox, which can disclose sensitive process memory, though the flaw does not by itself enable code execution. All users running Chrome versions before 153.0.8010.36 are affected. There is no CISA KEV listing, EPSS is low (0.2% probability of exploitation in 30 days, 7th percentile), and one public reference exists on the Chromium issue tracker, so no widespread in-the-wild exploitation is currently known.
What to do: Update Google Chrome to 153.0.8010.36 or later and verify the deployed version across managed endpoints (e.g., via chrome://settings/help or enterprise patch reporting). Until patched, limit exposure to untrusted web content on high-value systems, since the flaw is reachable through a crafted HTML page. Given the Medium severity, low EPSS, and no KEV entry, standard patch-cadence handling is reasonable, but browser updates should not be deferred long because the browser is the primary attack surface here.
| Google Chrome | all versions prior to 153.0.8010.36 (fixed in 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.