CVE-2026-87527: Critical Buffer overflow in WebGL
Buffer overflow in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Other sources
Chromium CVE-2026-87527: Buffer overflow in WebGL
— Microsoft
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium-based Edgeto a version that resolves this vulnerability.Fixed in 153.0.8010.36Patch Chromium CVE-2026-87527
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
How can I determine whether an installation is affected?
Check the installed Google Chrome version. Versions earlier than 153.0.8010.36 are affected.
What does an attacker need to exploit this issue?
The attacker can be remote and needs to cause the target to process a crafted HTML page. No local access is indicated in the available information.
What is the impact if exploitation succeeds?
Successful exploitation can allow arbitrary code execution outside Chrome's sandbox.