External risk intelligence

Chrome for Android WebGL Buffer Overflow Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-93372

This vulnerability affects a client-side web browser application. Exploitation requires a user to navigate to a crafted HTML page, meaning it is not a public-facing service, gateway, or network-accessible endpoint that can be reached proactively by an attacker. It is a client-side execution context.

Buffer Overflow

Google Chrome

before 153.0.8010.52

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security vulnerability has been identified in Google Chrome on Android. This issue could allow an attacker to execute malicious code remotely by luring a user to a specially crafted web page. The primary concern at this time is to confirm if our organization and its users are exposed to this type of threat.

  • Attackers can run code on devices.
  • Affects Chrome on Android.
  • Confirm relevance and user exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious website. This website would contain specially crafted code designed to exploit a weakness in how Chrome handles certain web graphics commands. Successfully triggering this weakness could allow the attacker's code to run with elevated privileges, potentially impacting the device.

  • Requires user to visit a malicious page.
  • Triggered by crafted HTML page content.
  • Allows arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

A buffer overflow vulnerability in Chrome's WebGL component on Android, when a user visits a malicious HTML page, could allow an attacker to execute code beyond the browser's sandbox. This could potentially impact the confidentiality, integrity, and availability of the affected Android device.

  • Arbitrary code execution outside the sandbox.
  • Via a crafted HTML page visited by user.
  • Compromise of device confidentiality, integrity, availability.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Google Chrome on Android is a critical buffer overflow that could allow remote code execution. Responsibility for addressing this likely falls to teams managing mobile application deployments and potentially vendor management if Chrome is deployed via enterprise channels. The first practical step is to identify all Android devices running vulnerable versions of Chrome, confirm their exposure, and then plan remediation based on risk.

  • Mobile application and vendor management teams.
  • Verify Android Chrome deployment and user access.
  • Coordinate user-facing updates and risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome on Android?

Google Chrome for Android is a web browser application used to access, display, and interact with internet content. It includes specialized components like WebGL, which the browser uses to render interactive 3D and 2D graphics directly within web pages using the device's hardware acceleration.

What does CVE-2026-93372 mean?

This vulnerability is categorized as a stack-based buffer overflow (CWE-121). In plain terms, the browser's graphics component fails to correctly manage the memory assigned to handle certain data. Because of this flaw, a specially crafted web page can push more data into a memory buffer than it can hold, overwriting adjacent memory and potentially allowing the execution of unauthorized code.

How is this vulnerability triggered?

An attacker must entice a user to navigate to a malicious website containing specially crafted HTML or WebGL code. Simply having the browser installed is not enough to trigger the issue; the flaw is only activated when the browser parses and renders the specific, malicious graphics commands contained within that web page.

Is my device at risk based on Halo Surface Signal?

Halo Surface Signal indicates this is a client-side issue rather than a public-facing service. Because exploitation requires a user to interact with a specific, malicious webpage, it is not an endpoint that attackers can scan and exploit automatically from the internet. The risk is localized to the behavior of individual users visiting untrusted sites.

Do I need to update Chrome?

Yes. If you manage mobile devices, start by identifying which Android devices are running versions of Chrome older than 153.0.8010.52. Coordinate with your mobile application management teams to ensure these devices receive the official update provided by Google, as this is the primary way to remediate the underlying flaw.

References