Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-78904

CVE-2026-78904: Google Chrome ANGLE RCE Vulnerability

CVE-2026-78904 is a type confusion remote code execution flaw in Google Chrome ANGLE that allows attackers to execute arbitrary code outside the sandbox. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-78904 Overview

CVE-2026-78904 is a type confusion vulnerability in ANGLE (Almost Native Graphics Layer Engine), the graphics abstraction layer used by Google Chrome to translate WebGL and OpenGL ES calls to native GPU APIs. The flaw affects Google Chrome versions prior to 152.0.7977.65. A remote attacker can exploit this issue by hosting a crafted HTML page that triggers the type confusion during graphics processing. Successful exploitation may allow arbitrary code execution outside the browser sandbox, giving the attacker code execution in the context of the user. The vulnerability is tracked under CWE-843 (Access of Resource Using Incompatible Type).

Critical Impact

Remote attackers can achieve arbitrary code execution outside the Chrome sandbox by luring users to a malicious web page.

Affected Products

  • Google Chrome for Desktop versions prior to 152.0.7977.65
  • Chromium-based browsers embedding vulnerable ANGLE builds
  • Applications using bundled Chromium components with affected ANGLE versions

Discovery Timeline

  • 2026-08-25 - CVE-2026-78904 published to NVD
  • 2026-08-27 - Last updated in NVD database

Technical Details for CVE-2026-78904

Vulnerability Analysis

The vulnerability resides in ANGLE, which mediates between Chrome's WebGL implementation and the underlying GPU drivers on Windows, macOS, and Linux. Type confusion occurs when code operates on a memory object while assuming it belongs to a different type than the one actually allocated. In ANGLE, this mismatch can be triggered through specifically structured WebGL calls issued from JavaScript in an attacker-controlled page.

Because ANGLE runs partly within the GPU process rather than the tightly restricted renderer, memory corruption here has historically enabled attackers to bypass Chrome's site isolation and sandbox boundaries. The advisory language explicitly notes potential code execution outside the sandbox, distinguishing this from renderer-only issues.

Root Cause

The root cause is improper type validation within ANGLE when handling graphics objects or shader-related structures. The engine treats a memory region as one type while it was allocated or initialized as another, allowing attacker-controlled data to be interpreted as trusted fields such as function pointers, vtable entries, or object metadata. See the Chromium Issue Tracker entry for tracking references.

Attack Vector

Exploitation requires a victim to visit a crafted HTML page in a vulnerable Chrome build. The page loads JavaScript that issues WebGL or Canvas operations designed to reach the flawed ANGLE code path. Once type confusion is triggered, the attacker manipulates memory layout to achieve control over program flow. Chained with a sandbox escape primitive already present in the ANGLE/GPU boundary, the attacker executes native code with the privileges of the Chrome GPU process.

No public proof-of-concept code is available at the time of writing.
Refer to the Google Chrome Stable Update advisory for vendor guidance:
https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html

Detection Methods for CVE-2026-78904

Indicators of Compromise

  • Chrome processes spawning unexpected child processes such as cmd.exe, powershell.exe, or shell interpreters shortly after web browsing activity
  • GPU process (chrome.exe --type=gpu-process) crashes or unusual memory allocation patterns preceding suspicious process creation
  • Outbound connections from Chrome-related processes to newly registered or low-reputation domains hosting HTML/JavaScript payloads

Detection Strategies

  • Inventory installed Chrome versions across the fleet and flag any build below 152.0.7977.65
  • Monitor endpoint telemetry for anomalous behavior originating from the Chrome GPU process, including memory injection and code execution primitives
  • Correlate browser navigation events with subsequent process, file, or network activity that deviates from normal browsing baselines

Monitoring Recommendations

  • Enable browser telemetry and forward Chrome crash reports to a centralized logging system for triage
  • Track DNS and proxy logs for user visits to unknown domains immediately preceding endpoint alerts
  • Alert on unsigned or unusual DLLs loaded into Chrome processes and on GPU process crashes correlated with network activity

How to Mitigate CVE-2026-78904

Immediate Actions Required

  • Update Google Chrome to version 152.0.7977.65 or later on all managed endpoints
  • Restart Chrome after updating so the patched binaries are actually loaded into memory
  • Verify that Chromium-based browsers and embedded WebViews in your environment have shipped equivalent ANGLE fixes

Patch Information

Google addressed CVE-2026-78904 in the Chrome Stable channel release documented in the Google Chrome Stable Update advisory. Administrators should deploy Chrome 152.0.7977.65 or later through their standard software distribution channels and confirm installation with version inventory queries.

Workarounds

  • Enforce enterprise policies that require the latest Chrome version and block launch of outdated builds
  • Restrict access to untrusted web content using URL filtering, isolation, or secure web gateway controls until patching is complete
  • Consider temporarily disabling WebGL via the HardwareAccelerationModeEnabled policy where operationally acceptable, understanding that this reduces attack surface but affects application compatibility
bash
# Verify installed Chrome version on Windows endpoints
reg query "HKLM\Software\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Verify installed Chrome version on macOS
defaults read /Applications/Google\ Chrome.app/Contents/Info CFBundleShortVersionString

# Verify installed Chrome version on Linux
google-chrome --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.