External risk intelligence

Chrome for Android WebGL Out of Bounds Write Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95329

This vulnerability affects a client-side web browser application. While it requires the user to load a crafted HTML page, the vulnerability exists within the local browser installation on the end-user's device, not as a public-facing network service, edge gateway, or server-side infrastructure.

Out-of-bounds Write

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability exists in WebGL within Google Chrome on Android, potentially allowing for code execution outside the browser's security sandbox. This occurs through a specially crafted HTML page, which could enable attackers to compromise user devices. The main concern is confirming relevance and exposure, as exploitation requires user interaction with a malicious web page.

  • A WebGL flaw may let code run outside the sandbox.
  • Users could be at risk if they visit a bad website.
  • Confirm if this affects your Android Chrome users.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage, which then exploits a flaw in Chrome's WebGL component. This could allow the attacker to execute their own code on the user's device, potentially escaping the browser's security sandbox.

  • User must visit a malicious webpage.
  • WebGL in the browser is triggered.
  • Arbitrary code execution outside sandbox.

Live Threat

Current exploitation, exposure, and threat context

An out-of-bounds write in Chrome's WebGL component could allow an attacker to execute arbitrary code when a user visits a malicious HTML page. This could affect the integrity and availability of the user's device, and potentially lead to the execution of unauthorized code.

  • User's browser and device.
  • User visits a malicious HTML page.
  • Arbitrary code execution outside sandbox.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Google Chrome on Android requires immediate attention from teams managing end-user devices and browser deployments. The first practical step is to inventory all Android devices running Chrome, determine their exposure to malicious websites, and confirm the Chrome version. Once identified, the accountable owner should plan for remediation, prioritizing business-critical systems and user impact.

  • Own the Chrome browser deployment and updates.
  • Verify Chrome version on Android devices.
  • Plan for Chrome browser updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome on Android?

Google Chrome for Android is the mobile version of the web browser. It uses a rendering engine to display websites and includes components like WebGL, which allows the browser to render high-performance 2D and 3D graphics directly within the web page. This vulnerability specifically impacts how the browser manages these graphics operations.

What does an out-of-bounds write mean in CVE-2026-95329?

This is a memory-related weakness classified as CWE-787. It occurs when a program attempts to write data past the intended end of a memory buffer. In this CVE, the WebGL component fails to safely handle graphics data, which can be manipulated to overwrite adjacent memory, potentially allowing an attacker to run unauthorized code.

How does an attacker trigger this WebGL vulnerability?

The vulnerability is triggered when a user navigates to a specifically crafted HTML page designed to exploit the WebGL flaw. It does not trigger through standard browser usage, background processes, or interactions with legitimate websites. The attack requires the user to actively visit the malicious site.

Is my device vulnerable according to Halo Surface Signal?

Halo Surface Signal identifies this as a client-side browser issue rather than a public-facing network service. Because the flaw resides within the local browser installation on a user's device, the risk is tied to individual user web activity rather than the exposure of internal servers or edge infrastructure to the open internet.

What is the first step to address this Chrome vulnerability?

Your priority is to identify which Android devices in your environment are running a version of Chrome older than 154.0.8037.57. Once you have an inventory of affected devices, coordinate the necessary browser updates to ensure users are running the patched software version.

References