CVE-2026-103628: Out of bounds write in WebGL
Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154.0.8037.97
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome versions are affected?
Google Chrome versions prior to 154.0.8037.97 are affected. Updating to 154.0.8037.97 or later addresses the reported issue.
What does an attacker need to exploit this vulnerability?
The issue can be exploited remotely through a crafted HTML page. The description does not indicate that local access or prior authentication is required.
What is the potential impact of successful exploitation?
A successful exploit could allow arbitrary code execution outside the Chrome sandbox. Chromium rates the issue as Critical.