CVE-2026-87596
PoC massOut-of-Bounds Read in ANGLE in Google Chrome Prior to 153.0.8010.36
CVE-2026-87596 is an out-of-bounds read (CWE-125) in ANGLE, the graphics translation layer Google Chrome uses for GPU-accelerated rendering such as WebGL. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, causing ANGLE to read past a buffer boundary. The attacker gains the ability to read memory outside the Chrome sandbox, which is an information-disclosure issue (CVSS 4.3, medium, limited to confidentiality, though Chromium rates the bug High severity). Anyone running Google Chrome prior to 153.0.8010.36 is affected. There is no confirmed in-the-wild exploitation: EPSS puts the 30-day exploitation probability at roughly 0.2%, it is not in CISA KEV, and the only public reference is the Chromium issue tracker entry 536434693.
What to do: Update Chrome to 153.0.8010.36 or later and restart the browser (confirm via chrome://settings/help); administrators should verify fleet-wide versions and prioritize hosts whose users browse untrusted web content. No configuration mitigations are documented, but users on unpatched builds may reduce ANGLE attack surface by avoiding WebGL-heavy pages until they update.
| Google Chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.