Sceawere

Vulnerability Detail

CVE-2026-76046UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ANGLE Buffer Overflow in Chrome

Vulnerability Metadata

Severity
High
Score / CVSS
8.3
Creation Date
17h ago
Vendor
Google
Product
Chrome
Attack Type
Buffer overflow
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Buffer overflow in ANGLE in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.3",
  "pubDate": "2026-08-18T21:18:28.750Z",
  "pubdate": "2026-08-18T21:18:28.750Z",
  "executiveSummary": "This vulnerability is a buffer overflow security flaw affecting the ANGLE graphics engine component within Google Chrome on Android prior to version 151.0.7922.169.\nThe primary impact of this flaw is arbitrary code execution outside of the browser sandbox, allowing a compromised renderer process to escalate privileges and potentially compromise the underlying operating system.\nThe affected product is Google Chrome on Android, specifically versions predating 151.0.7922.169.\nThe risk implications are severe due to the potential breach of browser isolation boundaries, permitting sandbox escape.\nAttacker capabilities require initial control or compromise of the renderer process within the browser architecture.\nExploitation requirements dictate that the target must load a crafted HTML page designed to trigger the memory corruption condition within the vulnerable ANGLE component.",
  "technicalDetails": "The root cause of the vulnerability stems from a buffer overflow condition located within the ANGLE graphics translation layer in Google Chrome on Android.\nThe vulnerable component is the ANGLE library, which is responsible for translating OpenGL ES API calls to platform-specific graphics APIs such as Vulkan, OpenGL, or Direct3D.\nThe affected software versions include Google Chrome on Android prior to 151.0.7922.169.\nRegarding authentication and privilege requirements, the vulnerability does not require user authentication, but successful exploitation presupposes that an attacker has already compromised the unprivileged renderer process through a separate initial vector.\nNetwork exposure is relevant insofar as the victim must process content delivered via the network, specifically by rendering a crafted HTML page.\nThe step-by-step attack flow begins when a user navigates to or loads a maliciously crafted HTML page supplied by a remote attacker.\nUpon parsing the malicious HTML and associated graphic directives, the browser utilizes the vulnerable ANGLE component to process the input.\nAn improper bounds check or memory allocation error during this graphics processing phase results in a buffer overflow within the heap or stack memory structures managed by ANGLE.\nBecause the renderer process is initially restricted by the browser sandbox, the attacker leverages the arbitrary memory corruption primitive achieved via the buffer overflow to overwrite critical function pointers or control data.\nBy hijacking execution flow within the context of the vulnerable process, the payload behavior enables the attacker to break out of the constrained renderer sandbox.\nThe post-exploitation impact includes the execution of arbitrary code outside the sandbox with the privileges of the hosting application or system context, leading to potential full device compromise depending on system permissions and further escalation vectors."
}
CVE-2026-76046: ANGLE Buffer Overflow in Chrome (HIGH Severity, CVSS: 8.3) - Sceawere