Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-17655

CVE-2026-17655: Google Chrome ANGLE RCE Vulnerability

CVE-2026-17655 is a critical remote code execution flaw in Google Chrome's ANGLE component allowing sandbox escape through crafted HTML pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-17655 Overview

CVE-2026-17655 is an input validation flaw in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome to translate OpenGL ES calls to native graphics APIs. Chrome versions prior to 151.0.7922.72 fail to properly validate untrusted input processed by ANGLE. A remote attacker can exploit the flaw through a crafted HTML page to attempt a sandbox escape. Google labels the Chromium security severity as Critical. The weakness is classified under CWE-20: Improper Input Validation.

Critical Impact

A crafted web page can trigger a sandbox escape from the Chrome renderer, allowing code to run outside the browser's isolation boundary.

Affected Products

  • Google Chrome for Desktop versions prior to 151.0.7922.72
  • Chromium-based browsers embedding vulnerable ANGLE builds
  • Applications shipping with the pre-patch ANGLE component

Discovery Timeline

  • 2026-07-30 - CVE-2026-17655 published to the National Vulnerability Database
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-17655

Vulnerability Analysis

ANGLE sits between Chrome's renderer and the host graphics stack, translating WebGL and OpenGL ES calls into Direct3D, Metal, or Vulkan operations. The component processes untrusted graphics commands originating from web content. This CVE stems from insufficient validation of untrusted input reaching ANGLE from a renderer process. Because ANGLE code executes in a privileged context relative to the renderer sandbox, unchecked input can be leveraged to break out of the sandbox boundary. A successful exploit gives the attacker code execution outside the tab isolation layer that Chrome relies on to contain hostile web content. Google classifies the Chromium security severity as Critical, reflecting the sandbox-escape impact rather than a simple renderer crash.

Root Cause

The root cause is improper input validation ([CWE-20]) inside ANGLE. Data supplied by the renderer, which is itself driven by attacker-controlled JavaScript and WebGL content, is not sufficiently checked before use. See the Chromium Issue Tracker Entry for the upstream tracking record.

Attack Vector

Exploitation requires only that a user visit an attacker-controlled or compromised web page. The crafted HTML delivers WebGL or graphics API calls that pass malformed data to ANGLE. The attacker leverages the validation gap to escape the renderer sandbox and act with the privileges of the browser process. No authentication or additional user interaction beyond page navigation is required. As of publication, no public proof-of-concept exploit or in-the-wild exploitation has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS probability is 0.309% (percentile 23.2).

No verified exploitation code is available. Consult the Google Chrome Stable Update advisory for vendor-supplied technical context.

Detection Methods for CVE-2026-17655

Indicators of Compromise

  • Unexpected child processes spawned by chrome.exe or the Chrome GPU process following a browsing session
  • Crashes or unusual termination events in the Chrome GPU process (--type=gpu-process) correlated with WebGL-heavy pages
  • Outbound network connections initiated by browser helper processes to previously unseen domains after visiting untrusted content

Detection Strategies

  • Inventory installed Chrome and Chromium-derivative browser versions and flag any build older than 151.0.7922.72
  • Monitor endpoints for anomalous process ancestry originating from browser processes, particularly the GPU process
  • Correlate browser crash telemetry with subsequent process creation or file write activity on the same host

Monitoring Recommendations

  • Ingest Chrome crash and stability logs into a central log platform for retrospective hunting
  • Track WebGL-related error and crash patterns alongside DNS and HTTP telemetry to identify malicious pages
  • Alert on browser processes writing executables or loading unsigned modules outside the standard Chrome install path

How to Mitigate CVE-2026-17655

Immediate Actions Required

  • Update Google Chrome to version 151.0.7922.72 or later on all managed endpoints
  • Restart the browser after patching to ensure the vulnerable ANGLE binaries are unloaded from memory
  • Audit third-party Chromium-based browsers and Electron applications for updated ANGLE builds

Patch Information

Google addressed the flaw in Chrome Stable 151.0.7922.72. Deployment details and the full list of fixed issues are documented in the Google Chrome Stable Update release notes. Enterprise administrators should push the update through their existing Chrome Enterprise or software distribution tooling.

Workarounds

  • Enforce automatic Chrome updates through group policy or MDM until the patched build is confirmed installed
  • Restrict access to untrusted websites using web filtering or DNS-layer controls during the patch rollout window
  • Consider disabling hardware-accelerated graphics through the HardwareAccelerationModeEnabled policy as a temporary measure where operationally acceptable
bash
# Verify installed Chrome version on Windows endpoints
reg query "HKLM\SOFTWARE\Google\Chrome\BLBeacon" /v version

# Verify installed Chrome version on macOS endpoints
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

# Verify installed Chrome version on Linux endpoints
google-chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.