Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14397

CVE-2026-14397: Google Chrome ANGLE RCE Vulnerability

CVE-2026-14397 is a remote code execution flaw in Google Chrome's ANGLE component on Mac that enables sandbox escape through crafted HTML pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-14397 Overview

CVE-2026-14397 is an out-of-bounds write vulnerability in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome to translate OpenGL ES calls to native graphics APIs. The flaw affects Google Chrome on macOS in versions prior to 150.0.7871.46. A remote attacker can leverage a crafted HTML page to trigger memory corruption within the ANGLE component and potentially escape the Chrome sandbox. The weakness is classified under CWE-787 (Out-of-bounds Write). Google rated the underlying Chromium issue as Medium severity, while the calculated CVSS 3.1 score reflects the scope change associated with sandbox escape scenarios.

Critical Impact

Successful exploitation allows a remote attacker to perform a sandbox escape on macOS Chrome installations through a single visit to a malicious web page, leading to code execution outside the renderer's confinement.

Affected Products

  • Google Chrome for macOS prior to 150.0.7871.46
  • ANGLE graphics translation component bundled with Chromium
  • Chromium-based browsers on macOS that ship the vulnerable ANGLE build

Discovery Timeline

  • 2026-07-01 - CVE-2026-14397 published to NVD
  • 2026-07-02 - Last updated in NVD database

Technical Details for CVE-2026-14397

Vulnerability Analysis

The vulnerability resides in ANGLE, which translates WebGL and OpenGL ES API calls into Metal on macOS. An out-of-bounds write occurs when ANGLE processes attacker-controlled graphics data supplied through a crafted HTML page. Because ANGLE executes within the GPU process rather than the more restrictive renderer sandbox, memory corruption here provides a stronger primitive for breaking out of Chrome's process isolation model. The CVSS vector indicates network-based exploitation with user interaction, and a scope change consistent with sandbox escape.

The EPSS score is 0.223% as of 2026-07-02, reflecting a currently low predicted exploitation likelihood, though browser sandbox escapes historically become integrated into exploit chains once technical details emerge. See the Chromium Issue Tracker Entry for additional context.

Root Cause

The root cause is an out-of-bounds write [CWE-787] in ANGLE's handling of graphics resources on macOS. Insufficient bounds validation on data derived from WebGL or OpenGL ES calls allows a write past the intended buffer boundary. This corrupts adjacent memory in the GPU process, which can be shaped into a control-flow or data-only exploitation primitive.

Attack Vector

Exploitation requires a target user to visit a page controlled by the attacker in an unpatched Chrome build on macOS. The malicious page issues crafted WebGL calls that reach the vulnerable ANGLE code path. The renderer marshals these calls to the GPU process, where the out-of-bounds write triggers. Combined with a suitable heap layout, the attacker can pivot from GPU-process corruption to sandbox escape.

No verified public proof-of-concept has been released. Refer to the Google Chrome Update Announcement for the vendor's disclosure.

Detection Methods for CVE-2026-14397

Indicators of Compromise

  • Unexpected Chrome GPU process crashes on macOS endpoints, particularly those referencing ANGLE or Metal frames in crash logs
  • Chrome renderer or GPU child processes spawning shells, osascript, or unusual macOS binaries following web browsing activity
  • Outbound network connections from Chrome helper processes to previously unseen domains hosting WebGL-heavy content

Detection Strategies

  • Inventory installed Chrome versions across macOS fleets and flag any build below 150.0.7871.46
  • Monitor for anomalous child processes originating from Google Chrome Helper (GPU) on macOS
  • Correlate browser crash telemetry with subsequent process creation or persistence events on the same host

Monitoring Recommendations

  • Ingest Chrome crash dumps and macOS unified logs into a centralized analytics platform for hunting on ANGLE-related faults
  • Alert on privilege changes or new LaunchAgents created within minutes of a Chrome GPU process crash
  • Track WebGL-heavy URL categories in web proxy logs and correlate with endpoint activity on unpatched hosts

How to Mitigate CVE-2026-14397

Immediate Actions Required

  • Update Google Chrome on macOS to version 150.0.7871.46 or later across all managed endpoints
  • Restart Chrome after applying the update to ensure the vulnerable ANGLE code is unloaded from memory
  • Prioritize patching for users who routinely browse untrusted content or handle sensitive data

Patch Information

Google addressed CVE-2026-14397 in the Chrome Stable channel release documented in the Google Chrome Update Announcement. macOS users must be on Chrome 150.0.7871.46 or later. Chromium-based browsers that embed ANGLE should be updated once their vendors publish downstream fixes.

Workarounds

  • Enforce automatic Chrome updates through enterprise policy so users cannot defer the patch
  • Restrict access to untrusted sites via web filtering while the patch is being deployed
  • Disable hardware acceleration in Chrome as a temporary measure to reduce use of the vulnerable ANGLE code paths, accepting the associated performance impact
bash
# Verify Chrome version on macOS endpoints
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --version

# Enforce automatic updates via managed preferences
sudo defaults write /Library/Preferences/com.google.Keystone.Agent checkInterval -int 3600

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.