CVE-2026-93372
chrome: Stack-based Buffer Overflow (CVE-2026-93372)
criticalEPSS 0.4%
Description
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
googlechrome
153.0.8010.52fixed from 153.0.8010.52Metrics
Show all metrics
Severity
critical
88.95
no public PoC known
9.6
Published
2026-09-30 20:24 UTC
CWE-121
Weakness classes (CWE)
CWE-121Variant
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-21 15:04 UTC· nvd@nist.gov
- CPE Configuration: AND OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.52 OR cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
- Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html Types: Release Notes, Vendor Advisory
- Reference Type: Chrome: https://issues.chromium.org/issues/548085797 Types: Permissions Required
- CVE Modified2026-09-19 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-93372","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-93372","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-09-18 14:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- SSVC: {"id":"CVE-2026-93372","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-17 21:17 UTC· chrome-cve-admin@google.com
- Description: Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CWE: CWE-121
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93372.json">CVE-2026-93372</a>
- Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html