External risk intelligence

ANGLE Use After Free Vulnerability in Google Chrome

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95325

This vulnerability affects a client-side web browser. While it requires the user to load a crafted HTML page, the vulnerability itself is tied to the browser application on an endpoint, which is not an internet-facing service, edge gateway, or server-side component typically exposed to the public internet for remote connection.

Use After Free

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A use-after-free vulnerability in ANGLE, a component within Google Chrome, allows for potential arbitrary code execution outside the sandbox when a user visits a malicious HTML page. While the severity is rated Medium by Chromium, it's important to confirm if this affects your organization's managed Chrome environments.

  • Browser vulnerability allows code execution on user visit.
  • Attackers could exploit user interaction with web pages.
  • Verify if affected browsers are in use.

Attack Path

How an attacker could exploit the issue

A remote attacker can lure a user into visiting a malicious webpage. This webpage exploits a use-after-free vulnerability within ANGLE, a component of the Chrome browser. Successful exploitation could allow the attacker to execute code with elevated privileges outside the browser's security sandbox.

  • No authentication or privileges required.
  • Loading a malicious HTML page.
  • Potential for arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A use-after-free vulnerability in ANGLE within Google Chrome, when supported by a crafted HTML page, could allow a remote attacker to execute arbitrary code outside the sandbox. This could impact the integrity and confidentiality of the user's system.

  • User-controlled code execution.
  • Via crafted HTML page.
  • Arbitrary code outside sandbox.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome's ANGLE component requires action from teams responsible for managing endpoint security and user-facing applications. The first practical step is to identify all endpoints running affected versions of Chrome, confirm their exposure and criticality, and then coordinate remediation efforts.

  • Own by endpoint security or application teams.
  • Verify Chrome version and user exposure.
  • Plan coordinated update or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ANGLE component in Google Chrome?

ANGLE is an abstraction layer that translates graphics API calls, such as OpenGL, into the hardware-native formats used by the operating system, like DirectX or Vulkan. It acts as a translator, allowing Chrome to render 3D graphics and web content consistently across different computers and hardware configurations.

What does CWE-416 mean for CVE-2026-95325?

CWE-416 refers to a 'Use After Free' weakness. In this context, it means Chrome's memory management fails to properly clear a reference to an object after it has been deleted. If a malicious webpage triggers this, the browser may attempt to use that freed memory, potentially allowing an attacker to manipulate the system and run unauthorized code.

How is this vulnerability triggered?

An attacker triggers this by luring a user to a specially crafted HTML page. The browser does not become vulnerable just by being installed or running; it requires the user to actively navigate to the malicious site. Simply having the browser open to legitimate, safe websites does not initiate the flaw.

Is this vulnerability an internet-facing threat?

Halo Surface Signal notes that this vulnerability affects a client-side browser, not a server or gateway directly exposed to the internet. While a remote attacker provides the malicious content, the flaw itself lives on the endpoint. Therefore, it is a risk to user-facing environments rather than a traditional internet-facing infrastructure service.

What is the first step to address this Chrome issue?

You should begin by inventorying your managed endpoints to identify which devices are running a version of Chrome earlier than 154.0.8037.57. Once identified, coordinate with your IT or security team to deploy the latest update, which contains the fix for this memory handling error.

References