Junglewise Threat Intelligence

CVE-2026-84351: Google Chrome buffer overflow in GPU

CVE-2026-84351 · Severity: high · CVSS 8.3 · Published 2026-09-02

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome, a widely-used web browser, contains a buffer overflow vulnerability in its graphics processing unit (GPU) component on Windows. An attacker who has already compromised the browser's renderer process can exploit this flaw to break out of the browser's security sandbox and execute malicious code with full system privileges, potentially compromising the user's entire computer.

Technical details

A buffer overflow vulnerability exists in the GPU processing component of Google Chrome on Windows versions prior to 152.0.7977.75. The vulnerability requires an attacker to have already compromised the renderer process (the sandboxed component that interprets web content), and then deliver a specially crafted HTML page to trigger the overflow. Successful exploitation allows arbitrary code execution outside the browser sandbox, effectively bypassing Chrome's primary security boundary. Google has patched this issue in version 152.0.7977.75 and later. The attack vector is network-based but requires the precondition of a prior renderer process compromise.

Affected products

  • Google Chrome prior to 152.0.7977.75

Timeline

  • 2026-09-02: disclosed

References

Related threats