External risk intelligence

Chrome for Android WebGL Buffer Overflow Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95349

This vulnerability affects a client-side web browser application. While it requires the user to load a crafted HTML page, the vulnerable WebGL component is a local client-side library. It is not an internet-facing service, edge gateway, or server-side application that is reachable by default in common network deployments.

Buffer Overflow

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical buffer overflow vulnerability exists in the WebGL component of Google Chrome on Android, which could allow an attacker to execute malicious code remotely. This issue is particularly concerning as it bypasses standard security sandboxing.

  • Remote code execution risk in browser.
  • Browser security is critical for all users.
  • Confirm relevance to confirm exposure.

Attack Path

How an attacker could exploit the issue

An attacker could target users visiting a malicious webpage through their Android device's Chrome browser. By exploiting a buffer overflow vulnerability in the WebGL component, the attacker could gain the ability to execute arbitrary code, potentially leading to a compromise of the user's device outside of its normal security boundaries.

  • Requires visiting a malicious webpage.
  • Triggered by the WebGL component.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A buffer overflow in Chrome's WebGL component on Android could allow an attacker to execute code outside the browser's sandbox when a user visits a malicious HTML page. This could impact the device's overall security when supported by the advisory.

  • Arbitrary code execution outside sandbox.
  • User visits a crafted HTML page.
  • Compromise of device security.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Google Chrome browser on Android is affected by a critical buffer overflow vulnerability. Technical leaders should work with application owners and platform teams to identify affected devices. The first practical step is to confirm exposure to a crafted HTML page, assess business criticality, and then plan remediation based on risk.

  • Own the issue: Application owners and platform teams.
  • Verify first: Identify and confirm affected devices.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Google Chrome on Android?

Google Chrome on Android is a widely used mobile web browser that allows users to navigate the internet. It includes the WebGL component, a library used by the browser to render 2D and 3D graphics directly within web pages using the device's hardware.

How does CVE-2026-95349 cause a buffer overflow?

This vulnerability is classified as CWE-122, or a heap-based buffer overflow. It occurs when the browser's WebGL component attempts to write more data into a memory buffer than it can hold, potentially allowing an attacker to overwrite adjacent memory and execute arbitrary code.

What triggers the CVE-2026-95349 vulnerability?

The flaw is triggered when a user visits a specially crafted HTML page designed to exploit the WebGL component. Simply having Chrome installed or the browser open on a legitimate site does not trigger the bug; the browser must process the malicious graphics instructions.

Is my device vulnerable to this browser flaw?

Halo Surface Signal notes that since this is a client-side browser issue, it is not an internet-facing service or server that is reachable by default. The risk is limited to users who navigate to malicious web content using an outdated version of Chrome.

Do I need to update my Chrome browser?

Yes, the primary step is to update Chrome on affected Android devices to version 154.0.8037.57 or later. Technical teams should first identify devices running older versions and ensure they are updated to address the security gap.

References