Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-79138

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 9.6

Описание

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in chromium-browser. An out-of-bounds write vulnerability in ANGLE, a component used for graphics rendering, could allow a remote attacker to execute malicious code. This vulnerability can be exploited by tricking a user into visiting a specially crafted web page. Successful exploitation could lead to arbitrary code execution, potentially allowing the attacker to take control of the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 6webkitgtkOut of support scope
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7webkitgtk3Not affected
Red Hat Enterprise Linux 7webkitgtk4Affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8mozjs60Not affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2523850chromium-browser: angle: chromium-browser: Arbitrary Code Execution via out-of-bounds write in ANGLE

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 2 месяцев назад

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 9.6
nvd
около 2 месяцев назад

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
около 1 месяца назад

Chromium: CVE-2026-79138 Out of bounds write in ANGLE

CVSS3: 9.6
debian
около 2 месяцев назад

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...

CVSS3: 9.6
github
около 2 месяцев назад

Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

9.6 Critical

CVSS3