CVE-2026-84351
massGPU buffer overflow in Google Chrome on Windows enables sandbox escape
CVE-2026-84351 is a buffer overflow (CWE-121) in the GPU process of Google Chrome on Windows, fixed in version 152.0.7977.75. A remote attacker can trigger it by luring a user to a crafted HTML page, but the flaw's full impact requires the attacker to have already compromised the renderer process. From there, the bug allows arbitrary code execution outside Chrome's sandbox, giving the attacker broader access to the host with high confidentiality, integrity, and availability impact. All users of Google Chrome on Windows running versions prior to 152.0.7977.75 are affected; non-Windows builds are not implicated in this advisory. As of now there is no known in-the-wild exploitation, no public proof-of-concept, the issue is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Update Google Chrome on Windows to 152.0.7977.75 or later, which is available via Chrome's built-in auto-update; verify the patched version at chrome://settings/help. Organizations should use enterprise update management (e.g., Chrome Browser Cloud Management or MDM policies) to confirm all Windows endpoints have received the fix. As an interim mitigation, note that exploitation requires an already-compromised renderer process, so keeping renderer exploits patched and exercising caution with untrusted web content reduces risk until updates are applied.
| Google Chrome (Windows) | prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Buffer overflow in GPU in Google Chrome on on Windows prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.