Sceawere

Vulnerability Detail

CVE-2026-95350UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

ANGLE Buffer Overflow in Chrome

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
7h ago
Vendor
Google
Product
Chrome
Attack Type
Buffer overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-29T18:17:27.920Z",
  "pubdate": "2026-09-29T18:17:27.920Z",
  "executiveSummary": "A critical memory corruption vulnerability exists within the ANGLE graphics abstraction layer integrated into Google Chrome on Android. This vulnerability is classified as a buffer overflow, which occurs when an application writes data beyond the boundaries of an allocated memory block. Successful exploitation allows a remote, unauthenticated attacker to achieve arbitrary code execution on the target device.\nThe flaw stems from insufficient boundary checking during graphics processing, which can be triggered by a specially crafted HTML page. Because the vulnerability allows for remote execution outside the browser sandbox, it poses a severe threat to the integrity and confidentiality of the entire Android system. The impact of this exploit is classified as Critical, as it provides a pathway for an attacker to bypass browser-level security controls, potentially leading to unauthorized data access, persistence, or full system compromise. Users are at significant risk if they visit malicious web content, as no user interaction beyond navigating to a compromised site is strictly required for the exploitation process.",
  "technicalDetails": "The vulnerability resides within the ANGLE (Almost Native Graphics Layer Engine) component of the Chromium project. ANGLE is responsible for translating OpenGL ES API calls into platform-specific graphics APIs, such as Vulkan, Direct3D, or Metal. On Android, this involves complex memory management for shader compilation, vertex buffer object (VBO) handling, and state tracking. The root cause is a heap-based buffer overflow triggered during the processing of malicious graphics commands provided via the web content.\nThe exploitation flow begins when a remote attacker hosts a crafted HTML page containing malicious WebGL or WebGPU calls. When the target user visits this page, the browser's rendering engine initiates a request to the ANGLE library to process graphics primitives. By supplying malformed inputs or exceeding predefined buffer capacity limits during attribute parsing or vertex data validation, the attacker induces a heap overflow.\nSpecifically, the overflow occurs because the ANGLE library fails to perform rigorous bounds checking on user-supplied data before copying it into memory allocated for internal processing. By precisely controlling the size and content of the overflow, an attacker can overwrite adjacent memory structures, such as object pointers or function pointers, within the heap.\nOnce the attacker successfully overwrites a critical control structure—such as a vtable entry or a function pointer—they can redirect the execution flow of the Chromium renderer process. Given the complexity of the memory layout, an attacker typically utilizes a combination of heap spraying techniques to place a malicious payload (shellcode or Return-Oriented Programming chains) in a predictable location. By triggering the execution of the corrupted pointer, the attacker gains the ability to execute arbitrary code within the context of the renderer process.\nBecause the exploit involves bypassing the browser sandbox, the attacker can leverage the compromised renderer process to interact with system APIs or exploit subsequent vulnerabilities in the Android kernel or privileged service processes. This transition from sandboxed execution to system-wide code execution effectively undermines the Chromium security model. The vulnerability affects all versions of Google Chrome on Android prior to 154.0.8037.57. No local authentication is required, and the attack is delivered entirely over the network via standard web protocols."
}
CVE-2026-95350: ANGLE Buffer Overflow in Chrome (CRITICAL Severity, CVSS: 9.6) | Sceawere