External risk intelligence

ANGLE Buffer Overflow in Chrome for Android Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95350

The vulnerability exists in a web browser, which is an application primarily designed to access, render, and interact with arbitrary content from the public internet. Exploitation requires a user to navigate to a crafted HTML page, making the web-browsing surface a commonly exposed and reachable vector in standard deployment scenarios.

Buffer Overflow

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in ANGLE, used by Google Chrome on Android, could allow attackers to execute code outside of the browser's secure environment. This occurs through a specially crafted webpage, posing a risk if users access malicious sites.

  • Code execution flaw in Android Chrome.
  • Affects user browsing, potentially exposing systems.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by luring a user to a malicious website containing a specially crafted HTML page. If the user visits this page using a vulnerable version of Google Chrome on Android, the browser component responsible for rendering graphics could be tricked into executing unauthorized code. This could allow the attacker to gain control of actions outside the browser's normal security boundaries.

  • Requires user interaction with a malicious page.
  • Triggered by viewing a crafted HTML page.
  • Risk: Arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A buffer overflow vulnerability in ANGLE within Google Chrome on Android could allow a remote attacker to execute arbitrary code outside the sandbox when a user visits a crafted HTML page. This could impact the confidentiality, integrity, and availability of the affected application and device.

  • System and user data could be affected.
  • Exposure could happen via a malicious HTML page.
  • Code execution outside the sandbox is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The buffer overflow vulnerability in ANGLE, affecting Google Chrome on Android, requires immediate attention from teams responsible for managing end-user device security and application deployments. The first practical step is to identify all Android devices running the affected version of Chrome, confirm their exposure to external web content, and then prioritize remediation efforts based on the criticality of the assets and the potential for exploitation.

  • Application owners and mobile device administrators own this issue.
  • Verify user exposure to crafted HTML pages.
  • Coordinate vendor updates and user communication.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the ANGLE component in Google Chrome on Android?

ANGLE is a software layer within Chrome that translates web-based graphics commands into the native language used by the Android operating system. It allows the browser to efficiently render complex visual content and 3D graphics on your device. When this component processes data incorrectly, it can create significant security gaps in the underlying browser architecture.

What does CVE-2026-95350 mean by a buffer overflow?

This vulnerability is a buffer overflow (CWE-122), which happens when a program writes more data into a temporary storage area—the buffer—than it is designed to hold. In CVE-2026-95350, a malicious webpage sends too much data to the ANGLE graphics engine. This causes the extra data to spill over, potentially allowing an attacker to overwrite critical memory and run unauthorized code.

How is this vulnerability triggered?

The flaw is triggered when a user opens a specially crafted HTML page in a vulnerable version of Chrome on Android. The malicious page uses complex graphics commands designed to crash or confuse the ANGLE component. Simply having the browser installed does not trigger the bug; the user must actively navigate to and load the malicious content for the vulnerability to be activated.

Is my device at risk from CVE-2026-95350?

According to Halo Surface Signal, this vulnerability is highly relevant because web browsers are designed to interact with untrusted content from the public internet. Because the browser is a primary interface for external sites, devices that frequently access diverse web content are at a higher risk of encountering the malicious pages required to trigger this issue.

How do I fix this security flaw?

To address this issue, you must ensure that Google Chrome on all affected Android devices is updated to version 154.0.8037.57 or later. Since the flaw resides within the browser application itself, installing the official vendor update provided by Google is the standard way to replace the vulnerable component with a secure version that correctly manages data buffers.

References