Skip to main content
Vulnerability Database/CVE-2026-106304

CVE-2026-106304: Google Chrome ANGLE RCE Vulnerability

CVE-2026-106304 is an out of bounds read flaw in Google Chrome ANGLE component that enables remote attackers to read memory outside the sandbox through malicious HTML pages. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-106304 Overview

CVE-2026-106304 is an out-of-bounds read vulnerability [CWE-125] in ANGLE, the graphics abstraction layer used by Google Chrome to translate OpenGL ES calls to native graphics APIs. The flaw affects Google Chrome versions prior to 155.0.8059.39. A remote attacker can read memory outside the sandbox by serving a crafted HTML page to a victim. Google classifies the Chromium security severity as Medium. Exploitation requires user interaction, specifically the victim visiting an attacker-controlled web page. The vulnerability leaks process memory contents rather than enabling direct code execution.

Critical Impact

Remote attackers can read memory outside the renderer sandbox through a crafted HTML page, potentially exposing sensitive process data.

Affected Products

  • Google Chrome versions prior to 155.0.8059.39
  • Chromium-based browsers incorporating the vulnerable ANGLE component
  • Desktop builds across Windows, macOS, and Linux stable channels

Discovery Timeline

  • 2026-10-06 - CVE-2026-106304 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-106304

Vulnerability Analysis

The vulnerability resides in ANGLE (Almost Native Graphics Layer Engine), the component that Chrome uses to translate WebGL and OpenGL ES calls into Direct3D, Metal, or Vulkan commands. An out-of-bounds read occurs when ANGLE accesses memory beyond the intended buffer boundary during graphics processing. The condition is reachable through JavaScript running in a web page that issues crafted WebGL operations. The read discloses memory contents that should remain inaccessible to the renderer context, which Google describes as reading memory outside the sandbox.

Because the issue is a read rather than a write, it does not grant arbitrary code execution. However, leaked memory may contain pointers, tokens, or data from other browser components useful for building subsequent exploit chains.

Root Cause

The root cause is improper validation of bounds [CWE-125] within ANGLE processing logic. Google has not published the specific function or commit publicly in the referenced disclosure. Full technical details are tracked in Chromium Issue #553124799, which may remain restricted pending broader patch adoption.

Attack Vector

Exploitation requires a victim to load a crafted HTML page in an unpatched Chrome build. The page uses WebGL APIs to drive ANGLE into the vulnerable code path. No authentication is required, and the attack can be delivered through any channel capable of serving HTML, including compromised websites, malvertising, or links in email. The scope change indicates that leaked data crosses the renderer sandbox boundary.

No verified public exploit code or proof-of-concept has been published. See the Google Chrome Releases announcement for the vendor advisory.

Detection Methods for CVE-2026-106304

Indicators of Compromise

  • Chrome browser processes running versions earlier than 155.0.8059.39 after the patch release window
  • Browser crashes or renderer process restarts correlated with WebGL-heavy pages from untrusted origins
  • Outbound connections from user workstations to newly registered domains hosting WebGL content

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag builds below 155.0.8059.39
  • Monitor endpoint telemetry for Chrome renderer crashes referencing ANGLE modules such as libGLESv2.dll or libEGL.dll
  • Correlate web proxy logs with user navigation to detect visits to pages serving unusual WebGL shader payloads

Monitoring Recommendations

  • Enable browser version reporting through enterprise management tools such as Chrome Browser Cloud Management
  • Centralize endpoint and proxy logs in a SIEM to correlate browser activity with suspicious page loads
  • Track Chromium security advisory feeds to confirm patch deployment status across managed devices

How to Mitigate CVE-2026-106304

Immediate Actions Required

  • Update Google Chrome to version 155.0.8059.39 or later on all Windows, macOS, and Linux endpoints
  • Restart browser sessions after update deployment to ensure the patched binaries are loaded
  • Verify Chromium-based browsers such as Edge, Brave, and Opera have incorporated the upstream ANGLE fix

Patch Information

Google released the fix in the Chrome stable channel update documented in the Chrome Releases blog post. Administrators should push the update through managed deployment channels. Chromium downstream vendors typically release corresponding patches within days of the upstream disclosure.

Workarounds

  • Disable WebGL via enterprise policy using the DefaultWebGLSetting or equivalent flag where business workflows allow
  • Restrict browsing to trusted sites through URL allowlists until patching completes
  • Use site isolation and ensure the --site-per-process flag remains enabled to limit cross-origin data exposure
bash
# Verify installed Chrome version on Linux endpoints
google-chrome --version

# Example enterprise policy to disable WebGL (Windows registry)
# HKLM\Software\Policies\Google\Chrome\DefaultWebGLSetting = 2

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.