CVE-2026-76036Patch(google / android)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Peaked 3d ago at 2 mentions (2026-08-19); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
androidchrome

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-08-19: 2Mentions · 2026-08-20: 1Mentions · 2026-08-21: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-21: 1Patch / Workaround · 2026-08-27: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 1Technical Details · 2026-08-21: 1Technical Details · 2026-08-27: 108-1908-2008-2108-27
Signal classification1 categories
Patch
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-192
Patch2
2026-08-201
Patch1
2026-08-211
Patch1
2026-08-271
Patch1
Full discourse5 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Patch

    🌐🚨 **GOOGLE PATCHES TWO CRITICAL CHROME FLAWS IN WEBGL AND DAWN** **CyberSignal Daily ✓ · 🌐 Browser Security · August 19, 2026** 🎯 **Two critical memory-safety vulnerabilities have been fixed in Chrome's graphics stack.** The vulnerabilities are: 🔥 **CVE-2026-76034 — WebGL** 🔥 **CVE-2026-76036 — Dawn** Both are described as: 💥 **buffer-overflow vulnerabilities** Potential consequences can include: 🔴 browser crashes 🔴 memory corruption 🔴 potentially arbitrary code execution in attack scenarios ### 🔄 FIXED CHROME RELEASE Google moved Chrome Stable to: 🪟 Windows/macOS — **151.0.7922.169/.170** 🐧 Linux — **151.0.7922.169** The rollout is occurring progressively. ### 🧠 WHY BROWSER PATCHING MATTERS Browsers process: 🌐 untrusted websites 📷 graphics 🎥 multimedia 📜 scripts every day. A serious graphics-engine vulnerability therefore lives extremely close to attacker-controlled content. ### 📌 CURRENT PICTURE 🚨 Two critical vulnerabilities 🎨 WebGL + Dawn affected 💥 Memory-safety issues ✅ Chrome update released > **The browser is one of the most exposed applications on an endpoint—keeping it current is basic attack-surface reduction.** 🔗 **Sources:** Cyber Security News • Google Chrome #CyberSecurity #Chrome #Google #WebGL #CVE #BrowserSecurity #CyberNews

    Post summary

    The message announces that Google has released Chrome patches addressing two critical buffer‑overflow vulnerabilities in WebGL and Dawn, with no evidence of active exploitation or PoC availability.

    0001058
    98 followersView on X
  • CSIRT TELCONET@CSIRT_Telconet
    Patch

    Google corrige 2 vulnerabilidades críticas de Chrome en WebGL y Dawn (CVE-2026-76034 y CVE-2026-76036) que podrían permitir ejecución de código. Más información: https://csirt.telconet.net/comunicacion/boletines-servicios/google-corrige-dos-vulnerabilidades-criticas-de-chrome-en-webgl-y-dawn/ https://t.co/0RzPYKBA1u

    Post summary

    Google has released patches for two critical Chrome vulnerabilities (CVE‑2026‑76034 and CVE‑2026‑76036) that could allow code execution via WebGL and Dawn.

    01000104
    865 followersView on X
  • Tech Start XYZ@TechStartXYZ
    Patch

    Os 2 pontos críticos corrigidos: • CVE-2026-76034 (WebGL): Buffer overflow na API gráfica JavaScript, permitindo injeção de comandos arbitrários fora do isolamento. • CVE-2026-76036 (Motor Dawn): Falha no backend de WebGPU, explorando a integração profunda com o hardware para execução remota de código (RCE). Além delas, outras 13 falhas graves de Use-After-Free e Type Confusion no motor V8 foram fechadas.

    Post summary

    The text announces that two critical CVEs—one a WebGL buffer overflow allowing command injection, the other a WebGPU backend flaw enabling remote code execution—have been fixed, but provides no PoC, exploit, or patch details.

    1000031
    168 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Chrome の脆弱性 CVE-2026-76034/76036 (Critical) が FIX:WebGL と Dawn に RCE の恐れ https://iototsecnews.jp/2026/08/19/google-fixes-two-critical-chrome-flaws-in-webgl-and-dawn-update-your-browser/ Google Chrome のグラフィックス処理を担う描画コンポーネントにおいて、境界外のメモリ領域へデータを書き込んでしまう制御上の欠陥が潜んでいたことが、一連の問題の背景として挙げられます。これらの不具合が放置された場合、悪意ある Web サイトの閲覧を通じた任意の命令の実行/システムの予期せぬ停止/重要データの破壊といった重大な影響を与える恐れがあります。本件の脆弱性である CVE-2026-76034/CVE-2026-76036 への有効な対応策として、最新の修正パッチを組み込んだバージョンへの迅速な自動更新/システム管理ツールを用いた一括適用/稼働端末における適用状態の監視が強く推奨されます。 #Chrome #CVE202676034 #CVE202676036 #Google #Vulnerability

    Post summary

    Google has released patches for two critical Chrome flaws (CVE‑2026‑76034/76036) that allow out‑of‑bounds memory writes and RCE via WebGL and Dawn; users are urged to apply updates immediately.

    00000135
    510 followersView on X
  • Hunt-Benito@HB_CyberSec
    Patch

    CVE-2026-76036: CVSS 9.6. One createTexture() call - depth format, 259x127, mipmaps - overflows Chrome's GPU process on PowerVR phones. Code exec outside the sandbox; the fix reinstates a 2007-era rule. Patch: 151.0.7922.169. #Android #Chrome #WebGPU https://www.hunt-benito.com/blog/rendering-code-outside-the-sandbox-cve-2026-76036-critical-dawn-webgpu-buffer-overflow-in-chrome-on-android/ https://t.co/3gP4ifgDlD

    Post summary

    The article discloses CVE-2026-76036 with technical details and a CVSS score, notes how the overflow leads to code execution, and confirms a patch (151.0.7922.169) was released, but it offers no PoC or evidence of active exploitation.

    0000054
    3 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---

Explore more