CVE-2026-17676

Google · Chrome

An inappropriate implementation in the ANGLE graphics library allows a sandbox escape in Google Chrome on Android.

Executive summary

A critical sandbox escape in Google Chrome on Android, stemming from an insecure implementation in the ANGLE library, permits full system compromise.

Vulnerability

This vulnerability is caused by an inappropriate implementation within the ANGLE (Almost Native Graphics Layer Engine) component. An attacker who has already compromised the renderer process can leverage this flaw to perform a sandbox escape when the user visits a crafted HTML page.

Business impact

The vulnerability is rated with a critical CVSS score of 9.6. Because it allows a sandbox escape, an attacker could potentially gain elevated privileges on the host device, leading to full system compromise, data theft, and the installation of persistent malicious software.

Remediation

Immediate Action: Update Google Chrome on all Android devices to version 151.0.7922.72 or later.

Proactive Monitoring: Monitor for unusual system-level behavior or unauthorized application installation attempts on mobile devices.

Compensating Controls: Utilize mobile threat defense (MTD) solutions to detect malicious application behavior that may follow a successful sandbox escape.

Exploitation status

Public Exploit Available: No (no confirmed public exploit exists in current data).

Analyst recommendation

Given the critical CVSS score of 9.6, this vulnerability represents an extremely high risk. Security teams must ensure that all Android devices running Chrome are updated to version 151.0.7922.72 immediately to prevent exploitation of this sandbox escape.