External risk intelligence

Buffer overflow in ANGLE in Chrome for Android allows remote code execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95281

The vulnerability exists in a web browser, which is an internet-facing application by design. Users frequently encounter crafted HTML pages while browsing the internet, making the exposure of this component to external content common and expected in normal web usage.

Buffer Overflow

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in ANGLE, used by Google Chrome on Android, could allow attackers to execute code outside the browser's secure sandbox by luring users to malicious websites. This flaw presents a significant risk as it targets a widely used application and enables powerful remote code execution.

  • Code execution risk via malicious websites.
  • Affects Chrome on Android; confirms wider impact.
  • Assess exposure and potential need for controls.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into visiting a malicious website. When the user accesses this crafted HTML page, it triggers a buffer overflow within the ANGLE component of the Chrome browser on Android. Successful exploitation allows the attacker to execute arbitrary code, potentially bypassing the browser's security sandbox.

  • Requires user interaction via a crafted page.
  • Triggered by loading malicious HTML.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A critical buffer overflow in ANGLE, a component within Google Chrome on Android, could allow a remote attacker to execute arbitrary code outside the sandbox. This could occur when a user visits a specially crafted HTML page, potentially leading to a compromise of the device's integrity.

  • Arbitrary code execution.
  • Visiting malicious web pages.
  • Sandbox escape and system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Determine ownership by identifying teams responsible for the Android operating system and the Chrome browser, such as platform or application owners. The first step is to locate all instances of the affected technology, assess their business criticality and exposure, and then assign an owner to plan remediation based on risk.

  • Assign ownership to platform and application teams.
  • Verify browser and OS instances and their reachability.
  • Plan remediation based on risk and criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ANGLE component used in Google Chrome?

ANGLE is a graphics abstraction layer that translates industry-standard graphics API calls into the underlying hardware's native API. It allows Google Chrome on Android to reliably render 2D and 3D graphics content, such as animations and web-based games, across a diverse range of Android devices and graphics drivers.

What does CVE-2026-95281 mean by buffer overflow?

This vulnerability is classified as CWE-122, a heap-based buffer overflow. It occurs when the ANGLE component attempts to write more data into a reserved memory space than it can hold. Because this memory is incorrectly handled, it can overwrite adjacent data, potentially allowing a malicious website to run unauthorized commands on your device.

How is this vulnerability triggered?

The flaw is triggered when a user navigates to a specifically crafted HTML page. The malicious code is processed by the ANGLE component during page rendering. Simply having Chrome installed does not trigger the issue; the malicious code must be actively executed by the browser while viewing a website controlled by an attacker.

Is my device at risk from this Chrome vulnerability?

According to Halo Surface Signal, this vulnerability is considered highly relevant because Chrome is an internet-facing application. Because users regularly browse various websites, the exposure to potentially malicious content is inherent to how the software is used, increasing the risk for devices running versions prior to 154.0.8037.57.

How do I address CVE-2026-95281 on my Android devices?

To secure your devices, you should update Google Chrome to version 154.0.8037.57 or later. If you manage multiple devices, identify the teams responsible for your mobile environment and ensure the latest browser version is deployed. Prioritize these updates across your mobile fleet to mitigate the risk of remote code execution.

References