CVE-2026-78989

Google · Chrome

An out of bounds read vulnerability in the ANGLE graphics engine of Google Chrome for Windows allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical out of bounds read vulnerability in Google Chrome on Windows allows remote attackers to achieve arbitrary code execution by enticing users to visit a malicious webpage.

Vulnerability

This vulnerability involves an out of bounds read within the ANGLE component, which is used for hardware-accelerated graphics. An unauthenticated remote attacker can trigger this flaw through a crafted HTML page, potentially breaking out of the browser sandbox to execute arbitrary code.

Business impact

The ability for an attacker to execute arbitrary code outside the browser sandbox poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data exfiltration, and the installation of persistent malware, justifying the 9.6 CVSS score. This vulnerability represents a significant threat to endpoint integrity and organizational data privacy.

Remediation

Immediate Action: Update all instances of Google Chrome on Windows to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for anomalous browser behavior or unexpected process execution patterns originating from the Chrome process.

Compensating Controls: Ensure that browser-based security features, such as site isolation and enhanced safe browsing, are enabled, and consider deploying endpoint detection and response (EDR) solutions to identify sandbox escape attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical severity and the potential for sandbox escape, administrators must prioritize the deployment of the browser update across all Windows workstations. Failure to patch allows a significant window of opportunity for attackers to leverage this memory corruption flaw for unauthorized system access.

More Google CVEs

Sources