Junglewise Threat Intelligence

CVE-2026-79215: Google Chrome integer overflow in WebGL

CVE-2026-79215 · Severity: high · CVSS 8.8 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions to access websites and web applications. An integer overflow vulnerability in its WebGL graphics component could allow attackers to execute arbitrary code with full system privileges by tricking users into visiting a malicious webpage, bypassing Chrome's security sandbox and potentially compromising the entire device.

Technical details

An integer overflow vulnerability exists in WebGL, a web graphics API in Google Chrome versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to craft a malicious HTML page that triggers the integer overflow, leading to memory corruption and arbitrary code execution outside the browser sandbox. The attack requires no user authentication and is reachable via network simply by serving a crafted webpage; the attacker must convince a user to visit the malicious page. No public exploit code is known to be circulating in the wild. Google patched the vulnerability in Chrome 152.0.7977.65 released on August 25, 2026.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-79215 disclosed in Chrome 152.0.7977.65 stable release
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats