Sceawere
Vulnerability Detail
CVE-2026-95281UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
ANGLE Buffer Overflow in Chrome
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 9h ago
- Vendor
- Product
- Chrome
- Attack Type
- Buffer overflow
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-09-29T18:17:19.507Z",
"pubdate": "2026-09-29T18:17:19.507Z",
"executiveSummary": "A critical memory corruption vulnerability exists within the ANGLE graphics abstraction layer integrated into Google Chrome on Android. This vulnerability is classified as a buffer overflow, a memory safety issue that occurs when data exceeds the bounds of an allocated buffer.\nThe vulnerability allows a remote, unauthenticated attacker to execute arbitrary code outside the browser's sandbox environment. By enticing a user to navigate to a specifically crafted HTML page, an attacker can trigger the overflow, potentially leading to full system compromise or persistence on the affected Android device.\nGiven the severity rating of 'Critical' and the potential for sandbox escape, this flaw represents a significant risk to user data and device integrity. Exploitation requires no user interaction beyond visiting a malicious web page, making it highly dangerous for mobile users. All users running Chrome for Android versions prior to 154.0.8037.57 are at risk and are strongly advised to apply updates immediately to mitigate potential remote code execution (RCE) scenarios.",
"technicalDetails": "The vulnerability resides within the ANGLE (Almost Native Graphics Layer Engine) component of the Chromium project, which is utilized by Google Chrome on Android to translate OpenGL ES calls into underlying graphics APIs like Vulkan or GLES. The root cause is a heap-based buffer overflow stemming from insufficient bounds checking during the processing of graphics-related data within the ANGLE rendering pipeline.\nThe attack flow begins when an attacker directs a target user to a malicious webpage containing a crafted HTML payload. This payload leverages WebGL or other graphics-intensive APIs to send malformed data structures to the ANGLE component. Because the buffer allocation logic fails to properly validate the size of incoming data, the crafted input overwrites adjacent memory addresses within the heap. This memory corruption allows the attacker to manipulate the execution flow of the application by overwriting function pointers or sensitive object metadata.\nBecause ANGLE operates in a context where it interacts with the underlying GPU drivers, successful exploitation of this heap overflow can lead to a sandbox escape. By carefully controlling the overflow, the attacker can hijack the program execution path, bypassing browser-level security restrictions. This enables the execution of arbitrary shellcode with the privileges of the browser process or potentially higher-level system privileges depending on the specific environment and the nature of the overflow.\nThe vulnerability is present in versions of Google Chrome on Android prior to 154.0.8037.57. Exploitation is facilitated over the network through standard web navigation, requiring no prior authentication or local access. Once the memory corruption occurs, the malicious payload can execute arbitrary code, which may result in data theft, the installation of malicious applications, or total device compromise. The absence of adequate bounds validation in the rendering engine allows this exploit to transition from a memory-unsafe condition to full control of the application's instruction pointer."
}