CVE-2026-76034: Buffer overflow in WebGL
Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Other sources
Chromium: CVE-2026-76034 Buffer overflow in WebGL
— Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Google Chrome / Chromium-based browsers (WebGL)to a version that resolves this vulnerability.Fixed in 151.0.7922.169 - Compensating control
Because the issue affects WebGL exploitation via a crafted HTML page, restrict WebGL/renderer access to untrusted content by using browser/site controls (e.g., disable WebGL for untrusted sites if supported) until the browser is updated.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which Chrome installations are affected?
Users of Google Chrome versions earlier than 151.0.7922.169 are affected. The issue is in WebGL and has been rated Critical by Chromium.
What does exploitation require and what is the impact?
An attacker needs to induce a user to load a crafted HTML page. Successful exploitation can execute arbitrary code outside Chrome's sandbox.