Description
Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-10-06
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Integer Overflow
Action: Immediate Patch
AI Analysis

Impact

An integer overflow in the WebGL implementation of Google Chrome for Android permits a remote attacker to craft an HTML page that can trigger undefined behavior, enabling execution of arbitrary code outside Chrome’s sandbox. This flaw jeopardizes confidentiality, integrity, and availability by potentially allowing an attacker to run code with the privileges of the browser process, thereby compromising the entire host device.

Affected Systems

The vulnerability affects Google Chrome versions for Android prior to 155.0.8059.39. Devices running any earlier Android build that includes this Chrome release are susceptible. Exact patch notes are referenced in the official Chrome release blog.

Risk and Exploitability

Chromium rates the flaw as High severity and lists it as an integer overflow (CWE-190). The CVSS score is 9.6, indicating critical risk. The EPSS score is unavailable, and the vulnerability is not present in the CISA KEV catalog, suggesting no widespread active exploitation yet. However, the attack requires a crafted HTML page, most likely delivered over the network, and hinges on the browser’s WebGL code path. Because the flaw can lead to arbitrary code execution beyond the sandbox, the risk remains high until a vendor patch is applied. Users should consider the attack vector to be web-based and perform continuous monitoring of Chrome updates.

Generated by OpenCVE AI on October 7, 2026 at 03:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Chrome to version 155.0.8059.39 or newer, which contains the integer‑overflow fix.
  • If an update is not yet available, disable WebGL or GPU acceleration via browser flags or policy to eliminate the vulnerable code path.
  • Employ app‑level sandboxing or device security configurations that isolate browser execution and restrict rendering capabilities to reduce exposure.

Generated by OpenCVE AI on October 7, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WebGL Enables Remote Code Execution on Android Chrome chromium-browser: Integer overflow in WebGL
References
Metrics threat_severity

None

threat_severity

Important


Wed, 07 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in WebGL Enables Remote Code Execution on Android Chrome

Wed, 07 Oct 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in WebGL in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-190
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T03:56:11.889Z

Reserved: 2026-10-06T16:33:06.945Z

Link: CVE-2026-106239

cve-icon Vulnrichment

Updated: 2026-10-06T21:02:33.186Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:50.800

Modified: 2026-10-07T13:53:26.303

Link: CVE-2026-106239

cve-icon Redhat

Severity : Important

Publid Date: 2026-10-06T18:41:09Z

Links: CVE-2026-106239 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:45:10Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound