Use after free in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Chromium: CVE-2026-78905 Type confusion in ANGLE
Chromium: CVE-2026-79048 Out of bounds write in ANGLE
Chromium: CVE-2026-17750 Use after free in ANGLE
Chromium: CVE-2026-14412 Insufficient validation of untrusted input in ANGLE
Chromium: CVE-2026-14385 Heap buffer overflow in ANGLE
A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash.
External Reference:
https://www.mozilla.org/en-US/security/advisories/mfsa2017-22/#CVE-2017-7824