AI analysis
An out-of-bounds read (CWE-125) in Google Chrome's WebGL implementation, fixed in 154.0.8037.92, allowed a remote attacker to read memory outside the browser's renderer sandbox. The flaw is triggered when a victim visits a crafted HTML page that abuses WebGL graphics calls, requiring no privileges and only user interaction to open the page (CVSS 3.1: 4.7, network vector, low complexity, scope changed, low confidentiality impact). Successful exploitation is an information disclosure — potentially leaking process memory such as pointers, tokens, or page contents — but does not by itself permit code execution, modification of data, or denial of service. All Chrome versions prior to 154.0.8037.92 are affected, with the fix shipping in the Chrome 154 stable update that resolved 32 security issues, including a critical bug in ANGLE, the graphics translation layer that WebGL relies on. Google rates the Chromium severity as High, but there is no known public proof-of-concept, the CVE is not on CISA's KEV list, and no exploitation in the wild has been reported.
What to do: Update Google Chrome to 154.0.8037.92 or later immediately via Help > About Google Chrome, and verify that auto-update has applied on managed fleets. Keep in mind that Chromium-derived browsers (e.g., Edge, Brave, Opera, Vivaldi) inherit the same vulnerable WebGL code until each vendor ships a build on the patched Chromium base, so check their update channels as well. Because this is a sandbox-escaping information disclosure triggered by simply visiting a malicious page, treat unpatched kiosk, VDI, and shared-browser deployments as higher priority for remediation.
Affected
| Google Chrome | All versions prior to 154.0.8037.92 (fixed in 154.0.8037.92) |
Estimated exposure
mass≈3 billion users (Chrome's global install base, roughly 65% browser market share) — Estimated from Chrome's publicly reported user base of roughly 3 billion and its dominant browser market share; every installation running a version older than 154.0.8037.92 was reachable via a malicious web page until Chrome's automatic…