Executive brief
Google Chrome's WebGL graphics engine contains a buffer overflow vulnerability that allows attackers to execute arbitrary code outside the browser sandbox by tricking users into viewing a malicious webpage. This type of attack can lead to complete compromise of the affected device, including theft of data and installation of malware, with no user awareness beyond visiting a link.
Technical details
The vulnerability is a buffer overflow in the WebGL graphics rendering component of Google Chrome on Android. The flaw allows a remote attacker to trigger memory corruption by crafting a malicious HTML page that exploits improper bounds checking in WebGL operations. No authentication or user interaction beyond viewing the page is required; the attack is triggered automatically when the page loads. Successful exploitation results in arbitrary code execution outside the Chrome sandbox, granting the attacker full device-level access. The vulnerability was patched in Chrome version 153.0.8010.52 released on September 17, 2026.
Affected products
- Google Chrome prior to 153.0.8010.52 on Android
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Version 153.0.8010.52 and later