ZeroHour

CVE-2026-84351

mass

GPU buffer overflow in Google Chrome on Windows enables sandbox escape

CVSS 3.1
8.3 high
EPSS
<1%p20
Published
()
Modified
AI analysis

CVE-2026-84351 is a buffer overflow (CWE-121) in the GPU process of Google Chrome on Windows, fixed in version 152.0.7977.75. A remote attacker can trigger it by luring a user to a crafted HTML page, but the flaw's full impact requires the attacker to have already compromised the renderer process. From there, the bug allows arbitrary code execution outside Chrome's sandbox, giving the attacker broader access to the host with high confidentiality, integrity, and availability impact. All users of Google Chrome on Windows running versions prior to 152.0.7977.75 are affected; non-Windows builds are not implicated in this advisory. As of now there is no known in-the-wild exploitation, no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Update Google Chrome on Windows to 152.0.7977.75 or later, which is available via Chrome's built-in auto-update; verify the patched version at chrome://settings/help. Organizations should use enterprise update management (e.g., Chrome Browser Cloud Management or MDM policies) to confirm all Windows endpoints have received the fix. As an interim mitigation, note that exploitation requires an already-compromised renderer process, so keeping renderer exploits patched and exercising caution with untrusted web content reduces risk until updates are applied.

Affected
Google Chrome (Windows)prior to 152.0.7977.75
Estimated exposure
masshundreds of millions of Windows devices running Chrome desktop builds older than the fixed version — Chrome holds roughly 60-65% of global browser market share and is the default or dominant browser on Windows desktops worldwide, so the unpatched Windows install base is plausibly in the hundreds of millions, though this is an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.