Skip to finding
important · Browser

A crafted WebGL page can execute code outside Chrome’s sandbox.

Affects

Google Chrome desktop and Android browsers processing attacker-controlled WebGL content.

The victim need only load attacker-controlled HTML in an affected Chrome build.

Detail and 4 sources

The WebGL path performs an out-of-bounds write that permits arbitrary code execution outside the browser sandbox.

Chrome shipped corrected desktop builds 154.0.8037.97 and 154.0.8037.98, but the available evidence does not establish whether every route back to a pre-fix build is closed.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026