CVE-2026-87527
9.6Google · Chrome
A buffer overflow vulnerability in WebGL allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Executive summary
A critical buffer overflow vulnerability in Google Chrome allows unauthenticated remote attackers to execute arbitrary code, posing a severe risk to system integrity.
Vulnerability
This is a buffer overflow flaw within the WebGL component of Google Chrome. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a specially crafted HTML page, leading to potential code execution outside the browser sandbox.
Business impact
The ability to execute arbitrary code outside the sandbox represents a total compromise of the affected client machine. Given the CVSS score of 9.6, this vulnerability carries a critical severity, as it allows for full confidentiality, integrity, and availability loss. Successful exploitation could lead to data exfiltration, installation of persistent malware, or lateral movement within the corporate network.
Remediation
Immediate Action: Update all Google Chrome installations to version 153.0.8010.36 or later immediately to resolve the vulnerable WebGL component.
Proactive Monitoring: Monitor endpoint logs for unusual browser activity or unexpected process spawns originating from the Chrome browser process.
Compensating Controls: Deploy endpoint protection solutions that can detect and block malicious code execution attempts or unauthorized browser-based memory manipulation.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical severity of this buffer overflow, immediate patching is required to prevent potential remote code execution. Organizations should prioritize the deployment of the update to all endpoints running Chrome to mitigate the risk of sandbox escape and subsequent system compromise.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry