CVE-2026-78948
Google · Chrome
A buffer overflow vulnerability in the WebGL component of Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Executive summary
A critical buffer overflow vulnerability in Google Chrome enables remote code execution, posing a severe risk to system integrity and user data privacy.
Vulnerability
The flaw is a buffer overflow (CWE-122) within the WebGL component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to navigate to a specifically crafted HTML page, leading to arbitrary code execution outside the browser sandbox.
Business impact
The ability for an attacker to execute code outside the Chrome sandbox represents a total compromise of the affected client machine. Given the CVSS score of 9.6, this vulnerability carries a critical severity rating, as it could lead to unauthorized access to sensitive corporate data, persistent malware installation, or complete system takeover.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Review web proxy and browser access logs for suspicious navigation patterns or attempts to load malformed WebGL content.
Compensating Controls: Ensure that browser isolation solutions or endpoint protection platforms are active to detect and block malicious payloads associated with browser-based exploits.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability is highly severe because it bypasses the primary security boundary of the browser. Organizations should prioritize the deployment of the latest Chrome update across all workstations to neutralize the risk of remote code execution.