ZeroHour

CVE-2026-93372

mass

Critical WebGL Buffer Overflow in Google Chrome for Android

CVSS 3.1
9.6 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-93372 is a buffer overflow (CWE-121) in the WebGL component of Google Chrome on Android, fixed in Chrome 153.0.8010.52. A remote attacker can trigger it by luring a user to a crafted HTML page that renders malicious WebGL content, causing memory corruption in the browser process. Successful exploitation allows arbitrary code execution outside the sandbox, which defeats Chrome's key containment boundary and grants the attacker significantly broader access on the device. All Chrome for Android users running versions prior to 153.0.8010.52 are affected; the flaw carries a Critical Chromium security severity rating. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and the issue is not on CISA's KEV list; it was patched as one of 16 flaws in the Chrome 153 release.

What to do: Update Chrome on Android to version 153.0.8010.52 or later via the Google Play Store and verify the version at chrome://version. Until patched, avoid following links from untrusted sources, since a crafted web page alone can trigger the flaw. Organizations should use MDM/enterprise policies to force the Chrome update fleet-wide, and desktop users should also apply the latest Chrome 153 release, which fixes 16 issues including two critical ones.

Affected
Google Chrome for Androidall versions prior to 153.0.8010.52
Estimated exposure
mass≈billions of users (Chrome for Android has 5B+ Google Play installs) — Chrome is the default and dominant browser on Android, with Play Store install counts exceeding 5 billion, so effectively the entire Chrome-on-Android installed base prior to 153.0.8010.52 is exposed until users update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.