Skip to content
GoogleCVE-2026-93372

Google Chrome: buffer overflow

Critical9.6CVE-2026-93372 · Published Sep 17, 2026 · updated Sep 21, 2026

Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 153.0.8010.52, < 153.0.8010.52153.0.8010.52
Details and references

More Google advisories

All Google
Advisory
Google Chrome: remote attacker could obtain cross-origin data
Medium4.3Sep 17
Google Chrome: type confusion
High8.8Sep 17
Google Chrome: missing authorization
Low3.1Sep 17
Google Chrome: improper authorization
Medium4.3Sep 17
Google Chrome: race condition
Low3.1Sep 17
Google Chrome: buffer overflow
High8.8Sep 17

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.