CVE-2026-79215

8.8

Google · Chrome

A remote code execution vulnerability exists in the Google Chrome WebGL component due to an integer overflow, allowing attackers to compromise the sandbox via a crafted HTML page.

Executive summary

An integer overflow vulnerability in the WebGL component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code outside the browser sandbox.

Vulnerability

This is an integer overflow vulnerability (CWE-190) triggered within the WebGL engine. An unauthenticated remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, potentially resulting in code execution outside the browser sandbox.

Business impact

The ability to execute arbitrary code outside the browser sandbox represents a significant security breach, potentially allowing an attacker to gain control over the underlying host system. Given the high CVSS score of 8.8, this vulnerability poses a severe threat to data confidentiality, system integrity, and endpoint security within the corporate environment.

Remediation

Immediate Action: Update all Google Chrome installations to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor endpoint security logs for abnormal browser process behavior or unexpected child process spawning originating from Google Chrome.

Compensating Controls: Deploy network-level protections and ensure that users are operating with the principle of least privilege to limit the impact if a browser compromise occurs.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a high risk of remote code execution, which could lead to a full system compromise. Organizations should prioritize updating all Chrome browser instances across their fleet to the patched version identified by the vendor to eliminate this exposure.

More Google CVEs

Sources