CVE-2026-87604
massOut-of-Bounds Read in Google Chrome's ANGLE Enables Sandbox Escape
CVE-2026-87604 is an out-of-bounds read (CWE-125) in ANGLE, the graphics translation library used by Google Chrome, with the flaw fixed in Chrome 153.0.8010.36. It is triggered when a user visits a crafted HTML page, and an attacker who has already compromised the Chrome renderer process can leverage the memory-safety bug to break out of the browser sandbox. Successful exploitation potentially allows arbitrary code execution outside the sandbox, giving the attacker access to the underlying system. All Google Chrome installations running versions prior to 153.0.8010.36 are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and EPSS currently puts the 30-day exploitation probability at only about 0.2%.
What to do: Update Google Chrome to 153.0.8010.36 or later and confirm the running version via the browser's About page, forcing a restart if an update is staged. Organizations managing Chromium-based browsers built from the same code base should apply the corresponding upstream ANGLE fix once their vendor ships it. Until patching completes, note that exploitation requires user interaction with a malicious page plus a prior renderer compromise, so standard web-browsing caution and renderer hardening reduce practical risk.
| google chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Out of bounds read in ANGLE in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.