Description
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-09-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution in Google Chrome by overflow of the WebGL stack
Action: Immediate Patch
AI Analysis

Impact

A buffer overflow in the WebGL implementation of Google Chrome allows a remote attacker to execute arbitrary code outside the browser’s sandbox by serving a specially crafted HTML page. The vulnerability is classified as Critical by Chromium security and would grant the attacker full control of the system on which the browser is running.

Affected Systems

All instances of Google Chrome older than version 153.0.8010.36 are affected irrespective of operating system. The vulnerability remains present in any build that contains the older WebGL code path.

Risk and Exploitability

The EPSS score for this issue is less than 1%, and it is not listed in CISA’s KEV catalog, while the vulnerability’s CVSS score is 9.6. Because the flaw can be triggered by any reachable web page, the attack vector is most likely remote over the network, and an attacker can bypass the sandbox whenever a user opens a malicious page. Given the severity and lack of a mitigated path, the potential impact is high.

Generated by OpenCVE AI on September 9, 2026 at 17:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later
  • Disable WebGL support via chrome://flags or an extension as a temporary countermeasure
  • Maintain a strict patch‑management policy and monitor for new advisories from Google

Generated by OpenCVE AI on September 9, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-10T03:55:59.186Z

Reserved: 2026-09-08T22:39:31.847Z

Link: CVE-2026-87527

cve-icon Vulnrichment

Updated: 2026-09-09T13:31:00.687Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:09.980

Modified: 2026-09-10T04:18:23.953

Link: CVE-2026-87527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T05:45:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow