Sceawere
Vulnerability Detail
CVE-2026-103628UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WebGL Out-of-Bounds Write Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 10h ago
- Vendor
- Product
- Chrome
- Attack Type
- Out of bounds write
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Out of bounds write in WebGL in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-10-02T16:16:43.937Z",
"pubdate": "2026-10-02T16:16:43.937Z",
"executiveSummary": "A critical out-of-bounds (OOB) write vulnerability exists within the WebGL implementation of Google Chrome, affecting versions prior to 154.0.8037.97. This flaw is classified as a critical security issue due to its potential for remote code execution (RCE) outside the browser's security sandbox.\nThe vulnerability originates from memory mismanagement during WebGL operations, allowing an attacker to manipulate memory buffers beyond their intended boundaries. By delivering a specially crafted HTML page to a target user, a remote attacker can trigger this memory corruption to gain control over the execution flow.\nThe implications are severe, as successful exploitation enables arbitrary code execution on the underlying host system, effectively bypassing the Chromium sandbox architecture designed to isolate web content. There are no specific user interaction requirements beyond visiting the malicious page, making this a high-risk vector for drive-by attacks.\nOrganizations and individual users are urged to update to version 154.0.8037.97 or later immediately to neutralize the threat posed by this RCE capability.",
"technicalDetails": "The vulnerability is rooted in an out-of-bounds write condition within the WebGL component of the Chromium browser engine. WebGL relies on the underlying GPU drivers and the browser's graphics stack to process complex rendering instructions; the defect occurs when the browser fails to correctly validate the size of data being written into a memory buffer allocated for graphics processing.\nWhen a web page submits a crafted sequence of WebGL commands, the engine performs operations that trigger a write operation beyond the allocated bounds of the heap-based buffer. This memory corruption allows an attacker to overwrite adjacent data structures, such as object pointers or return addresses, within the process address space.\nThe exploitation flow typically begins with heap grooming, where the attacker uses JavaScript to allocate and release memory blocks to create a predictable heap layout. Once the heap is in a desired state, the attacker triggers the WebGL OOB write to overwrite sensitive memory, such as a Function Pointer or an array length, enabling a primitive for arbitrary memory read/write.\nFollowing the initial memory corruption, the attacker likely executes a technique to bypass platform-specific exploit mitigations, such as Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP). By leveraging the corruption primitive to leak memory addresses, the attacker can locate the base addresses of necessary system libraries or browser modules.\nThe final stage of the attack involves injecting a malicious payload—often shellcode or a ROP (Return-Oriented Programming) chain—and redirecting the control flow of the browser process. Because the vulnerability allows execution outside the Chromium sandbox, the attacker can leverage the browser's process privileges to execute system-level commands, gain persistent access, or exfiltrate sensitive data from the user's operating system environment.\nThe affected component is the WebGL subsystem within Chromium. All versions of Google Chrome prior to 154.0.8037.97 are susceptible. Exploitation does not require prior authentication or elevated local privileges, as the browser processes the malicious WebGL instructions automatically upon page load, making the attack surface significantly large for any remote actor capable of hosting a web page."
}