Threat Advisory

Critical ANGLE Buffer Overflow Lets Attackers Corrupt Chrome Memory

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Google has released an urgent security update for the desktop browser, addressing numerous security flaws across core components. The rollout remediates multiple high-severity vulnerabilities, including severe memory corruption issues and type confusion bugs within foundational engines. The highest severity issue carries a critical CVSS score of 9.6, posing substantial risks for arbitrary code execution if successfully triggered. While active exploitation has not been publicly observed in the wild, the complexity and severity of these memory safety flaws demand immediate remediation. Administrators and users must prioritize deploying these updates to maintain endpoint integrity and prevent potential compromise.

CVE-2026-102331: This critical flaw involves a buffer overflow vulnerability within the ANGLE graphics translation layer, carrying a CVSS score of 9.6. The issue occurs when processing maliciously crafted web content during graphics rendering operations. Exploitation of this vulnerability can lead to memory corruption and potential system compromise. Affected components include graphics subsystems responsible for translating web graphics calls into native system interfaces.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Google has released an urgent security update for the desktop browser, addressing numerous security flaws across core components. The rollout remediates multiple high-severity vulnerabilities, including severe memory corruption issues and type confusion bugs within foundational engines. The highest severity issue carries a critical CVSS score of 9.6, posing substantial risks for arbitrary code execution if successfully triggered. While active exploitation has not been publicly observed in the wild, the complexity and severity of these memory safety flaws demand immediate remediation. Administrators and users must prioritize deploying these updates to maintain endpoint integrity and prevent potential compromise.

CVE-2026-102331: This critical flaw involves a buffer overflow vulnerability within the ANGLE graphics translation layer, carrying a CVSS score of 9.6. The issue occurs when processing maliciously crafted web content during graphics rendering operations. Exploitation of this vulnerability can lead to memory corruption and potential system compromise. Affected components include graphics subsystems responsible for translating web graphics calls into native system interfaces.[emaillocker id="1283"]

CVE-2026-102306: This vulnerability represents a critical use-after-free weakness within core browser components, rated at a 9.6 CVSS severity level. The flaw stems from improper memory management after objects are freed, leading to potential pointer dereference issues. Exploitation via crafted web inputs can allow arbitrary code execution within the browser context. This issue impacts memory structures associated with component rendering and lifecycle management.

CVE-2026-102316: This entry identifies a critical use-after-free defect inside core application engines, designated with a 9.6 CVSS score. The vulnerability arises when dangling pointers are improperly handled during dynamic resource allocation and deallocation phases. Attackers can leverage this flaw to manipulate heap layouts and achieve remote code execution. The affected component handles critical runtime operations and resource management tasks.

CVE-2026-102304: This flaw involves a critical use-after-free weakness in internal processing subsystems, carrying a CVSS severity rating of 9.6. The vulnerability occurs due to failure in clearing object references after memory release routines complete. Successful exploitation can compromise browser security boundaries and allow malicious code execution. The affected component manages internal state tracking and execution flows.

CVE-2026-102309: This critical vulnerability highlights a severe use-after-free condition within execution logic, assigned a CVSS score of 9.6. The defect permits memory re-allocation abuse following improper pointer clearance during complex processing tasks. Attackers could potentially exploit this condition to execute arbitrary instructions within the user context. The affected component handles core application logic and structural rendering operations.

CVE-2026-102308: This issue covers a critical use-after-free flaw located in memory handling routines, evaluated at a 9.6 CVSS score. The vulnerability emerges from improper lifetime tracking of allocated objects across processing cycles. Exploitation risk involves memory manipulation leading to arbitrary code execution capabilities. The affected component oversees critical data structures and runtime memory allocation.

CVE-2026-102299: This high-severity vulnerability involves a type confusion weakness within the JavaScript execution engine, carrying a CVSS score of 8.8. The flaw occurs when the engine incorrectly infers the object type during runtime script evaluation. Attackers can exploit this error to bypass security controls and achieve arbitrary code execution. The affected component manages script compilation and dynamic type resolution.

CVE-2026-102323: This high-severity entry identifies a type confusion flaw within core execution modules, rated at a CVSS score of 8.8. The vulnerability is triggered through specially crafted scripts that manipulate object type definitions during interpretation. Successful exploitation can lead to unauthorized memory access and potential system compromise. The affected component handles script processing and runtime type validation.

Timely patching and rigorous version control remain critical defenses against memory corruption exploits. Organizations should enforce automated update policies to ensure all desktop endpoints quickly receive required patches.

RECOMMENDATION:

We recommend you to update Chrome to version 154.0.8037.92/93.

THREAT PROFILE:

Tactic Technique Id Technique Sub-technique
Initial access T1566.001 Phishing Spearphishing Attachment
Initial access T1566.002 Phishing Spearphishing Link
Execution T1059.001 Command and Scripting Interpreter PowerShell
Persistence T1543.003 Create or Modify System Process Windows Service
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
Credential access T1555.003 Credentials from Password Stores Credentials from Web Browsers
Collection T1005 Data from Local System -
Command and control T1071.001 Application Layer Protocol Web Protocols

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu