CVE-2026-79215
8.8Google · Chrome
A remote code execution vulnerability exists in the Google Chrome WebGL component due to an integer overflow, allowing attackers to compromise the sandbox via a crafted HTML page.
Executive summary
An integer overflow vulnerability in the WebGL component of Google Chrome allows a remote, unauthenticated attacker to execute arbitrary code outside the browser sandbox.
Vulnerability
This is an integer overflow vulnerability (CWE-190) triggered within the WebGL engine. An unauthenticated remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, potentially resulting in code execution outside the browser sandbox.
Business impact
The ability to execute arbitrary code outside the browser sandbox represents a significant security breach, potentially allowing an attacker to gain control over the underlying host system. Given the high CVSS score of 8.8, this vulnerability poses a severe threat to data confidentiality, system integrity, and endpoint security within the corporate environment.
Remediation
Immediate Action: Update all Google Chrome installations to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor endpoint security logs for abnormal browser process behavior or unexpected child process spawning originating from Google Chrome.
Compensating Controls: Deploy network-level protections and ensure that users are operating with the principle of least privilege to limit the impact if a browser compromise occurs.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a high risk of remote code execution, which could lead to a full system compromise. Organizations should prioritize updating all Chrome browser instances across their fleet to the patched version identified by the vendor to eliminate this exposure.