Junglewise Threat Intelligence

CVE-2026-87527: Google Chrome buffer overflow in WebGL

CVE-2026-87527 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebGL graphics component contains a buffer overflow vulnerability that allows attackers to execute arbitrary code outside the browser's security sandbox via a malicious webpage. This bypasses Chrome's core sandboxing protections, giving attackers full system-level access from a remote attacker simply visiting a crafted website, potentially compromising user data, credentials, and system integrity.

Technical details

A buffer overflow exists in the WebGL implementation within Google Chrome versions prior to 153.0.8010.36. The vulnerability is triggered when processing specially crafted WebGL commands or data within an HTML page. The attack vector is network-based, requiring only that a user visit a malicious website—no user interaction beyond normal browsing is needed. Successful exploitation allows remote code execution outside the browser sandbox, granting attackers unrestricted access to the system. The vulnerability was reported by Google on 2026-08-18 and fixed in Chrome 153.0.8010.36, released on 2026-09-08.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87527 published on NVD
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36 released to stable channel

References

Related threats