ZeroHour

CVE-2026-87596

PoC mass

Out-of-Bounds Read in ANGLE in Google Chrome Prior to 153.0.8010.36

CVSS 3.1
4.3 medium
EPSS
<1%p9
Published
()
Modified
AI analysis

CVE-2026-87596 is an out-of-bounds read (CWE-125) in ANGLE, the graphics translation layer Google Chrome uses for GPU-accelerated rendering such as WebGL. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing ANGLE to read past a buffer boundary. The attacker gains the ability to read memory outside the Chrome sandbox, which is an information-disclosure issue (CVSS 4.3, medium, limited to confidentiality, though Chromium rates the bug High severity). Anyone running Google Chrome prior to 153.0.8010.36 is affected. There is no confirmed in-the-wild exploitation: EPSS puts the 30-day exploitation probability at roughly 0.2%, it is not in CISA KEV, and the only public reference is the Chromium issue tracker entry 536434693.

What to do: Update Chrome to 153.0.8010.36 or later and restart the browser (confirm via chrome://settings/help); administrators should verify fleet-wide versions and prioritize hosts whose users browse untrusted web content. No configuration mitigations are documented, but users on unpatched builds may reduce ANGLE attack surface by avoiding WebGL-heavy pages until they update.

Affected
Google Chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of Chrome installs potentially affected until the 153.0.8010.36 auto-update lands (Chrome is the dominant desktop browser) — Chrome holds roughly 60-65% desktop browser market share with a multi-billion-user installed base, so hundreds of millions to billions of installs were plausibly on a pre-153.0.8010.36 build at disclosure, with auto-update shrinking that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.