Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-78989

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 9.6
EPSS Низкий

Описание

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in ANGLE, a component of Google Chrome on Windows. A remote attacker could exploit an out-of-bounds read vulnerability by enticing a user to visit a specially crafted HTML page. This could potentially allow the attacker to execute arbitrary code outside of the browser's security sandbox.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7webkitgtk3Not affected
Red Hat Enterprise Linux 7webkitgtk4Affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2523795chromium-browser: angle: ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page

EPSS

Процентиль: 45%
0.0056
Низкий

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 2 месяцев назад

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
около 2 месяцев назад

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
около 1 месяца назад

Chromium: CVE-2026-78989 Out of bounds read in ANGLE

CVSS3: 9.6
debian
около 2 месяцев назад

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 15 ...

CVSS3: 9.6
github
около 2 месяцев назад

Out of bounds read in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 45%
0.0056
Низкий

9.6 Critical

CVSS3