Google Chrome addressed two high-severity heap buffer overflow vulnerabilities that could be used to help break out of the browser sandbox. CVE-2026-6296 affects ANGLE in Chrome versions prior to 147.0.7727.101 and could allow a remote attacker to potentially achieve a sandbox escape by luring a user to a crafted HTML page. The flaw is tracked as CWE-122 and carries a CVSS:3.1 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, indicating high impact across confidentiality, integrity, and availability.
Google also fixed CVE-2026-7353, a separate Skia heap buffer overflow affecting Chrome versions prior to 147.0.7727.138. Chromium rated the issue as high severity and said a remote attacker who had already compromised the renderer process could potentially use a crafted HTML page to achieve a sandbox escape. The bug is also classified as CWE-122 and was assigned the CVSS:3.1 vector AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H. Google linked both issues to Chrome release notes and Chromium issue tracker entries as part of the remediation.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE-2026-7353 record was updated to add a CVSS v3.1 vector and references to the Chrome Releases blog and Chromium issue tracker. The added scoring reflected high impact to confidentiality, integrity, and availability with required user interaction and scope change.
A heap buffer overflow vulnerability in Skia affecting Google Chrome versions prior to 147.0.7727.138 was published as CVE-2026-7353. Chromium described it as High severity, and exploitation could potentially enable a sandbox escape after renderer compromise via a crafted HTML page.
A critical heap buffer overflow vulnerability in ANGLE affecting Google Chrome versions prior to 147.0.7727.101 was recorded as CVE-2026-6296. The flaw could allow a remote attacker to potentially achieve a sandbox escape by luring a user to a crafted HTML page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.