Skip to content
Auto-CTI
Back to today
NEW CRITICAL A3

CVE-2026-87527: Critical Buffer Overflow in WebGL in Google Chrome prior to 153.0.8010.36

A NVD · · CVE-2026-87527

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

A sandbox bypass in Chrome WebGL enables attackers to execute code outside the browser sandbox, increasing the risk of full system compromise via crafted web pages.

Description

A critical buffer overflow vulnerability in the WebGL implementation of Google Chrome prior to version 153.0.8010.36 allows a remote attacker to execute arbitrary code outside the browser sandbox. The vulnerability is triggered via a crafted HTML page and is rated critical according to Chromium security severity. Since WebGL processes graphics operations directly at the GPU level, successful exploitation can lead to full system compromise. It is currently unclear whether the vulnerability is being actively exploited or if public PoC code is available.

Risk score

54
cvss base
45.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
45.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC