CVE-2026-76034

8.8

Google · Chrome

A heap buffer overflow in Google Chrome's WebGL component allows an unauthenticated, remote attacker to escape the sandbox and execute arbitrary code via a crafted HTML page.

Executive summary

A critical heap buffer overflow in the Google Chrome WebGL component could allow a remote attacker to escape the browser sandbox and execute arbitrary code on the host system.

Vulnerability

This is a heap buffer overflow (CWE-122) in the WebGL component. An unauthenticated attacker can trigger this flaw by convincing a user to visit a crafted HTML page, leading to sandbox escape and code execution in the browser process context.

Business impact

Successful exploitation allows an attacker to bypass critical browser security boundaries, leading to full system compromise or sensitive data theft. Given the CVSS score of 8.8, this vulnerability represents a high-severity risk to any organization relying on Chrome for business operations. The ability to achieve code execution via a simple web page visit makes this an ideal target for watering hole and drive-by download attacks.

Remediation

Immediate Action: Update Google Chrome to 151.0.7922.169 (Linux) or 151.0.7922.169/.170 (Windows, Mac) immediately.

Proactive Monitoring: Review web gateway logs for traffic directed toward suspicious or newly registered domains that may be hosting malicious HTML content.

Compensating Controls: Utilize endpoint security solutions that provide browser isolation or enhanced exploit protection to mitigate the impact of sandbox escapes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant threat to endpoint security. Organizations must ensure that automatic updates are enabled for all Chrome browser instances. Security teams should communicate the importance of avoiding suspicious web links to users until the update is deployed across the environment.

More Google CVEs

Sources