CVE-2026-93372
chrome: Stack-based Buffer Overflow (CVE-2026-93372)
Description
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Source: BSI
Affected operating systems
linux
debian / chromiumtrixie
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
153.0.8010.52fixed from 153.0.8010.52Metrics
Show all metrics
Weakness classes (CWE)
CWE-121Variant
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
cwe.mitre.org →
References & sources
- https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html
- https://issues.chromium.org/issues/553136980
- https://issues.chromium.org/issues/500417361
- https://issues.chromium.org/issues/520521197
- https://issues.chromium.org/issues/560039872
- https://issues.chromium.org/issues/550839154
- https://issues.chromium.org/issues/515493668
- https://issues.chromium.org/issues/553132214
- https://issues.chromium.org/issues/540051167
- https://issues.chromium.org/issues/548085797
- https://issues.chromium.org/issues/511832293
- https://issues.chromium.org/issues/541707261
- https://issues.chromium.org/issues/498411599
- https://issues.chromium.org/issues/513996595
- https://issues.chromium.org/issues/553130676
- https://issues.chromium.org/issues/556853443
- https://issues.chromium.org/issues/560121552
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-09-21 15:04 UTC· nvd@nist.gov
- CPE Configuration: AND OR *cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to (excluding) 153.0.8010.52 OR cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
- Reference Type: Chrome: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html Types: Release Notes, Vendor Advisory
- Reference Type: Chrome: https://issues.chromium.org/issues/548085797 Types: Permissions Required
- CVE Modified2026-09-19 04:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-93372","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-93372","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-09-18 14:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- SSVC: {"id":"CVE-2026-93372","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-17 21:17 UTC· chrome-cve-admin@google.com
- Description: Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- CWE: CWE-121
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93372.json">CVE-2026-93372</a>
- Reference: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0194356994.html
Linked CVEs
- CVE-2026-93387
Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-origin data via a cra…
mediumCVSSv3 4.3 - CVE-2026-93386
UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to…
mediumCVSSv3 5.4 - CVE-2026-93385
Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive information via a crafted…
mediumCVSSv3 6.5 - CVE-2026-93384
Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker leveraging social…
lowCVSSv3 3.7 - CVE-2026-93383
Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin data via a crafted…
mediumCVSSv3 4.3 - CVE-2026-93382
Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox v…
highCVSSv3 8.8 - CVE-2026-93381
Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering t…
highCVSSv3 8.8 - CVE-2026-93380
Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer process a…
lowCVSSv3 3.1 - CVE-2026-93379
Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolation via a crafted H…
mediumCVSSv3 4.3 - CVE-2026-93378
Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the renderer proce…
lowCVSSv3 3.1 - CVE-2026-93377
Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to execute arbitrary…
highCVSSv3 8.8 - CVE-2026-93376
Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social engineering to read…
mediumCVSSv3 6.3 - CVE-2026-93375
Incorrect reference resolution in Tracing in Google Chrome on on Windows prior to 153.0.8010.52 allowed a local attacker to potentially e…
highCVSSv3 8.1 - CVE-2026-93374
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary c…
criticalCVSSv3 9.6 - CVE-2026-93373
Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outside the sand…
criticalCVSSv3 9.6 - CVE-2026-93372
Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code outsid…
criticalCVSSv3 9.6