Sceawere

Vulnerability Detail

CVE-2026-19157UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ANGLE Out-Of-Bounds Write Sandbox Escape

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Out of bounds write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Out of bounds write in ANGLE in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-08-06T22:16:58.010Z",
  "pubdate": "2026-08-06T22:16:58.010Z",
  "executiveSummary": "This vulnerability is an out-of-bounds write weakness present in the ANGLE component of Google Chrome on Android prior to version 151.0.7922.109.\nThe security flaw carries a Chromium security severity rating of Critical and enables a remote attacker to potentially execute a sandbox escape.\nExploitation requires a targeted user to navigate to or interact with a maliciously crafted HTML page rendered by the affected browser.\nUpon successful exploitation, the adversary can bypass the browser security sandbox boundaries, posing severe risk implications to the underlying host operating system.\nThe combination of remote accessibility via web content and critical sandbox-breaking capability necessitates immediate remediation across all deployed instances.",
  "technicalDetails": "The vulnerability manifests as an out-of-bounds write memory corruption flaw located within the ANGLE (Almost Native Graphics Layer Engine) graphics subsystem utilized by Google Chrome on Android prior to version 151.0.7922.109.\nRoot cause analysis indicates improper bounds checking or memory management during the processing of graphics operations or shader execution invoked through web content.\nThe attack vector is entirely remote, requiring no prior authentication or local privileges beyond the ability to deliver a crafted HTML page containing malicious WebGL or rendering payloads to the targeted browser instance.\nThe attack flow proceeds as follows: First, the remote attacker entices a user to load the crafted HTML page within Google Chrome on Android. Second, the rendering engine processes the malicious content, triggering the out-of-bounds write condition inside the ANGLE component.\nThis memory corruption corrupts adjacent heap metadata or critical data structures within the rendering process memory space.\nBy carefully manipulating the heap layout and payload execution, the attacker leverages the memory corruption primitive to achieve arbitrary code execution or elevate privileges within the context of the rendering process.\nFinally, the payload executes capabilities that breach the security sandbox boundaries, allowing the adversary to transition from the constrained browser process to a broader execution context on the Android operating system, resulting in a successful sandbox escape."
}
CVE-2026-19157: ANGLE Out-Of-Bounds Write Sandbox Escape (CRITICAL Severity, CVSS: 9.6) - Sceawere