Executive brief
Google Chrome is a web browser used by billions of users worldwide for accessing web content. A buffer overflow vulnerability in the WebGL graphics component allows an attacker to execute arbitrary code outside Chrome's security sandbox by hosting a specially crafted webpage, potentially leading to complete system compromise. This affects all Chrome users on Windows, Mac, and Linux with versions prior to 152.
Technical details
The vulnerability is a buffer overflow in the WebGL (Web Graphics Library) component of Google Chrome prior to version 152.0.7977.65. The root cause is improper bounds checking when processing WebGL commands, allowing an attacker-controlled HTML page to write data beyond allocated memory. The attack vector is network-based, requiring only that a user visit a malicious webpage—no authentication or user interaction beyond normal browsing is required. Successful exploitation breaks out of Chrome's sandbox isolation, enabling arbitrary code execution with the privileges of the browser process. The vulnerability was patched in Chrome 152.0.7977.65 released August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65 release
- 2026-07-01: reported: Originally reported by Google