Description
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-09-01
Score: 8.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow occurs in the GPU component of Google Chrome on Windows. When a renderer process—already compromised or tricked—processes a specially crafted HTML page, the overflow allows execution of arbitrary code outside the browser sandbox. This fault is categorized as a high severity vulnerability in Chromium’s own assessment, indicating a significant threat to confidentiality, integrity, and availability of the affected system.

Affected Systems

The flaw affects Windows users running Google Chrome versions earlier than 152.0.7977.75. Any machine with the desktop Chrome browser installed on Windows and not yet updated to at least this release is vulnerable.

Risk and Exploitability

The EPSS score is not available, but the high severity classification indicates a serious risk. Because the exploit relies on a remote attacker delivering crafted HTML that triggers the overflow within the renderer process, the most likely attack vector is a malicious web page or a compromised site. The vulnerability is not listed in the CISA KEV catalog, meaning there have been no publicly confirmed exploits yet, though the lack of EPSS data does not preclude future exploitation. Systems that have not yet applied the patch remain at risk of remote code execution.

Generated by OpenCVE AI on September 2, 2026 at 04:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.75 or later.
  • If an update cannot be applied immediately, launch Chrome with the --disable-gpu flag or otherwise disable GPU acceleration in the settings to prevent the vulnerable code path from executing.
  • Ensure that Chrome receives automatic updates or periodically verify that the installed version is the latest supported release to maintain protection against future releases of this vulnerability.

Generated by OpenCVE AI on September 2, 2026 at 04:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Buffer overflow in GPU
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Important


Wed, 02 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 02 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-121
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-02T09:51:05.747Z

Reserved: 2026-09-01T16:21:17.052Z

Link: CVE-2026-84351

cve-icon Vulnrichment

Updated: 2026-09-02T09:50:59.090Z

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:28.983

Modified: 2026-09-02T10:17:10.263

Link: CVE-2026-84351

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-01T23:42:27Z

Links: CVE-2026-84351 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:15:05Z

Weaknesses