Sceawere

Vulnerability Detail

CVE-2026-95357UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome GPU Out-of-Bounds Write

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
7h ago
Vendor
Google
Product
Chrome
Attack Type
Out of bounds write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Out of bounds write in GPU in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-09-29T18:17:28.760Z",
  "pubdate": "2026-09-29T18:17:28.760Z",
  "executiveSummary": "A critical out-of-bounds write vulnerability exists within the GPU process of Google Chrome on Android. This vulnerability, stemming from improper memory handling, allows a remote attacker to achieve arbitrary code execution beyond the confines of the browser sandbox. By leveraging a specially crafted HTML page, an attacker can trigger memory corruption within the GPU subsystem. The impact of this flaw is severe, potentially leading to full compromise of the browser's security model, including unauthorized access to sensitive user data and arbitrary code execution on the underlying device. As the vulnerability resides in the GPU process, exploitation bypasses standard browser-level sandbox protections. The issue affects all versions of Google Chrome on Android prior to 154.0.8037.57. No user interaction beyond navigating to a malicious webpage is strictly required, although the attacker must successfully entice the victim to visit the crafted site. Given the criticality and the nature of sandbox escape vulnerabilities, immediate patching is essential to prevent potential exploitation.",
  "technicalDetails": "The vulnerability is an out-of-bounds (OOB) write flaw located within the GPU process of the Chromium engine. This occurs when the GPU component fails to properly validate the bounds of data during memory write operations, leading to an overwrite of adjacent memory locations. In the context of browser security, the GPU process often handles complex rendering tasks and shader compilations, making it a high-value target for exploitation.\nThe attack flow begins when a user visits a malicious website containing a crafted HTML page. The page contains malicious JavaScript or specific WebGL/WebGPU calls designed to trigger the vulnerable code path in the GPU process. When the GPU process attempts to process these inputs, the lack of boundary verification causes the application to write data outside of its allocated buffer.\nBy carefully grooming the heap memory, an attacker can control the data that is overwritten. This typically involves placing specific objects in memory prior to triggering the out-of-bounds write. Successful exploitation allows the attacker to corrupt function pointers or other critical control flow structures within the GPU process memory space. By redirecting the instruction pointer to attacker-controlled shellcode or executing a return-oriented programming (ROP) chain, the attacker gains the ability to execute arbitrary code.\nBecause the GPU process operates with elevated privileges compared to the standard renderer sandbox, achieving arbitrary code execution here represents a significant security breach. It effectively allows the attacker to break out of the Chromium sandbox, granting them the ability to interact with the system or access resources that would otherwise be restricted. The vulnerability is triggered remotely and does not require local authentication or specialized privileges on the target device, relying entirely on the victim's interaction with the malicious content.\nThe affected versions include all Google Chrome on Android releases prior to 154.0.8037.57. The primary component responsible for the failure is the memory management logic within the GPU process pipeline. The exploit is highly dangerous because it facilitates sandbox escape, thereby circumventing the primary security architecture designed to isolate browser processes from the operating system."
}
CVE-2026-95357: Google Chrome GPU Out-of-Bounds Write (CRITICAL Severity, CVSS: 9.6) | Sceawere