CVE-2026-76034Patch(google / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow in WebGL in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 5 signals
  • Peaked 4d ago at 2 mentions (2026-08-19); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-08-19: 2Mentions · 2026-08-20: 1Mentions · 2026-08-26: 1Mentions · 2026-08-27: 1Mentions · 2026-08-29: 1Patch / Workaround · 2026-08-19: 2Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-26: 1Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-08-29: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 1Technical Details · 2026-08-26: 1Technical Details · 2026-08-27: 108-1908-2008-2608-2708-29
Signal classification1 categories
Patch
6100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-192
Patch2
2026-08-201
Patch1
2026-08-261
Patch1
2026-08-271
Patch1
2026-08-291
Patch1
Full discourse6 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🌐🚨 **GOOGLE PATCHES TWO CRITICAL CHROME FLAWS IN WEBGL AND DAWN** **CyberSignal Daily ✓ · 🌐 Browser Security · August 19, 2026** 🎯 **Two critical memory-safety vulnerabilities have been fixed in Chrome's graphics stack.** The vulnerabilities are: 🔥 **CVE-2026-76034 — WebGL** 🔥 **CVE-2026-76036 — Dawn** Both are described as: 💥 **buffer-overflow vulnerabilities** Potential consequences can include: 🔴 browser crashes 🔴 memory corruption 🔴 potentially arbitrary code execution in attack scenarios ### 🔄 FIXED CHROME RELEASE Google moved Chrome Stable to: 🪟 Windows/macOS — **151.0.7922.169/.170** 🐧 Linux — **151.0.7922.169** The rollout is occurring progressively. ### 🧠 WHY BROWSER PATCHING MATTERS Browsers process: 🌐 untrusted websites 📷 graphics 🎥 multimedia 📜 scripts every day. A serious graphics-engine vulnerability therefore lives extremely close to attacker-controlled content. ### 📌 CURRENT PICTURE 🚨 Two critical vulnerabilities 🎨 WebGL + Dawn affected 💥 Memory-safety issues ✅ Chrome update released > **The browser is one of the most exposed applications on an endpoint—keeping it current is basic attack-surface reduction.** 🔗 **Sources:** Cyber Security News • Google Chrome #CyberSecurity #Chrome #Google #WebGL #CVE #BrowserSecurity #CyberNews

    Post summary

    The article announces that Google released Chrome 151.0.7922 to patch two critical buffer‑overflow vulnerabilities in WebGL and Dawn, emphasizing the importance of keeping browsers updated.

    0001058
    98 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    Patch

    Google corrige 2 vulnerabilidades críticas de Chrome en WebGL y Dawn (CVE-2026-76034 y CVE-2026-76036) que podrían permitir ejecución de código. Más información: https://csirt.telconet.net/comunicacion/boletines-servicios/google-corrige-dos-vulnerabilidades-criticas-de-chrome-en-webgl-y-dawn/ https://t.co/0RzPYKBA1u

    Post summary

    The announcement informs that Google has released patches for two critical Chrome vulnerabilities (CVE‑2026‑76034 and CVE‑2026‑76036) that could allow code execution.

    01000104
    865 followersView on X
  • Tech Start XYZ@TechStartXYZ
    Patch

    Os 2 pontos críticos corrigidos: • CVE-2026-76034 (WebGL): Buffer overflow na API gráfica JavaScript, permitindo injeção de comandos arbitrários fora do isolamento. • CVE-2026-76036 (Motor Dawn): Falha no backend de WebGPU, explorando a integração profunda com o hardware para execução remota de código (RCE). Além delas, outras 13 falhas graves de Use-After-Free e Type Confusion no motor V8 foram fechadas.

    Post summary

    The article announces that CVE-2026-76034 and CVE-2026-76036 have been fixed, describing their technical nature (buffer overflow and remote code execution), but offers no evidence of exploits or active attacks.

    1000031
    168 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    Google Chrome 151の追加更新でCritical 2件を修正 https://www.cybernote.click/2026/08/20/google-chrome-151-cve-2026-76034-76036-update/ #IT #Security #cybersecurity

    Post summary

    The post announces the Google Chrome 151 update that fixes two critical CVEs, focusing on the patch without technical or exploit details.

    0000071
    203 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Chrome の脆弱性 CVE-2026-76034/76036 (Critical) が FIX:WebGL と Dawn に RCE の恐れ https://iototsecnews.jp/2026/08/19/google-fixes-two-critical-chrome-flaws-in-webgl-and-dawn-update-your-browser/ Google Chrome のグラフィックス処理を担う描画コンポーネントにおいて、境界外のメモリ領域へデータを書き込んでしまう制御上の欠陥が潜んでいたことが、一連の問題の背景として挙げられます。これらの不具合が放置された場合、悪意ある Web サイトの閲覧を通じた任意の命令の実行/システムの予期せぬ停止/重要データの破壊といった重大な影響を与える恐れがあります。本件の脆弱性である CVE-2026-76034/CVE-2026-76036 への有効な対応策として、最新の修正パッチを組み込んだバージョンへの迅速な自動更新/システム管理ツールを用いた一括適用/稼働端末における適用状態の監視が強く推奨されます。 #Chrome #CVE202676034 #CVE202676036 #Google #Vulnerability

    Post summary

    Google Chrome released fixes for critical WebGL/Dawn RCE CVEs CVE-2026-76034/76036; users are urged to install the latest patch via automatic or manual updates.

    00000135
    510 followersView on X
  • Bussio28Team | Ciberseguridad@Bussio28Team
    Patch

    🚨 Vulnerabilidad crítica en Google Chrome: CVE-2026-76034 Un fallo de desbordamiento de búfer en WebGL podría permitir que un atacante ejecute código arbitrario fuera del sandbox de Chrome mediante una página HTML especialmente diseñada. ¿Qué significa esto en la práctica? Que visitar una web maliciosa o comprometida con una versión vulnerable podría ser suficiente para poner en riesgo el sistema. Según la información publicada, el ataque requiere interacción del usuario, pero no necesita privilegios previos y su impacto potencial sobre la confidencialidad, integridad y disponibilidad es alto. 🔎 Versiones afectadas: Chrome anteriores a 151.0.7922.169. ✅ Qué hacer: • Actualizar Chrome inmediatamente. • Comprobar la versión desde Menú → Ayuda → Información de Google Chrome. • Reiniciar completamente el navegador después de actualizar. • En organizaciones, revisar el inventario de versiones y forzar el despliegue del parche. • Vigilar comportamientos anómalos, como procesos inesperados iniciados desde Chrome. Google incluyó la corrección dentro de una actualización que resuelve 15 problemas de seguridad. Aunque no se ha confirmado públicamente explotación activa de esta CVE, esperar a que aparezcan ataques no es una estrategia de seguridad. Un navegador desactualizado puede convertirse en la puerta de entrada a credenciales, sesiones corporativas y datos sensibles. Parchear hoy cuesta minutos; responder a un incidente puede costar semanas. #Ciberseguridad #Vulnerabilidad #Chrome #GoogleChrome #CVE #CVE202676034 #InfoSec #CyberSecurity #SeguridadInformática #PatchManagement

    Post summary

    The post highlights a critical WebGL buffer overflow (CVE‑2026‑76034) in Chrome, details the technical risk, and provides clear mitigation steps—update the browser immediately and verify the version—but reports no active exploitation.

    0000057
    45 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more