Google Fixes Two Critical Chrome Flaws in WebGL and Dawn — Update Your Browser

Google has launched a brand new Chrome Steady channel replace that fixes two critical security vulnerabilities affecting graphics-related elements. Customers ought to replace their browsers as quickly as the discharge turns into obtainable for his or her gadget.

The replace strikes Chrome to model 151.0.7922.169/.170 on Home windows and macOS, whereas Linux customers obtain model 151.0.7922.169. Google stated the rollout will happen step by step over the approaching days and weeks.

The 2 vital points are tracked as CVE-2026-76034 and CVE-2026-76036. Each are buffer overflow vulnerabilities, a memory-safety flaw that may happen when software program writes extra information right into a reminiscence space than it was designed to carry.

Such bugs can result in browser crashes, information corruption, or probably arbitrary code execution in sure assault situations. CVE-2026-76034 impacts WebGL, Chrome’s interface for rendering interactive 2D and 3D graphics inside web sites.

On-line video games, visualizations, browser-based design instruments, and different graphics-heavy net purposes extensively use WebGL. A malicious web site may probably try and set off the flaw by way of specifically crafted WebGL content material.

The second difficulty, CVE-2026-76036, is a buffer overflow in Dawn. Daybreak is Chromium’s implementation of the WebGPU normal, a more recent graphics API supposed to supply net purposes with extra direct and environment friendly entry to graphics {hardware}.

As a result of WebGPU and associated graphics elements course of complicated information from net content material, reminiscence corruption points in these areas can signify a major browser safety danger.

Google credited its personal safety staff with reporting CVE-2026-76034 on July 15, 2026, and CVE-2026-76036 on July 28, 2026. The corporate has not publicly disclosed technical particulars, proof-of-concept code, or exploitation info.

It stated entry to bug reviews might stay restricted till most Chrome customers have put in the fixes, lowering the chance for attackers to reverse-engineer patches and weaponize the vulnerabilities.

In complete, the Chrome 151 Stable release includes 15 security fixes. Google additionally famous that it makes use of memory-error detection and fuzzing applied sciences, together with AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Management Move Integrity, libFuzzer, and AFL, to establish safety bugs throughout improvement.

CVE ID Severity Vulnerability sort Affected element Reporter Subject ID
CVE-2026-76034 Essential Buffer overflow WebGL Google 534923522
CVE-2026-76036 Essential Buffer overflow Daybreak Google 540087398
CVE-2026-76033 Excessive Inappropriate implementation CORS Google 516715010
CVE-2026-76037 Excessive Hyperlink following CredentialProvider Google 517612295
CVE-2026-76044 Excessive Race situation USB Google 522732244
CVE-2026-76039 Excessive Incorrect reference decision Core Google 525167753
CVE-2026-76040 Excessive Use-after-free Browser Google 534862220
CVE-2026-76035 Excessive Inappropriate implementation Media Google 536439844
CVE-2026-76042 Excessive Use of uninitialized useful resource GPU Google 536460270
CVE-2026-76046 Excessive Buffer overflow ANGLE Google 536581050
CVE-2026-76043 Excessive Incorrect calculation V8 Raghav Maheshwari 539350801
CVE-2026-76041 Excessive Info leak Skia Google 540027341
CVE-2026-76047 Excessive Kind confusion V8 ywatanabee 541251902
CVE-2026-76038 Excessive Kind confusion V8 un3xploitable && GF 541926503
CVE-2026-76045 Excessive Use-after-free WebGL OpenAI Codex Safety (amyb) 543082390

Customers can replace Chrome by opening the browser menu, deciding on Assist, then About Google Chrome. Chrome will routinely test for the newest obtainable construct and immediate customers to relaunch as soon as the replace has downloaded.

Organizations ought to guarantee managed Home windows, macOS, and Linux endpoints obtain the brand new Chrome model by way of their regular patch-management course of.

Safety groups also needs to monitor browser model compliance, notably on programs that commonly entry untrusted web sites or use web-based graphics purposes.

Google’s printed launch notes establish the affected builds and make sure that the replace comprises 15 safety fixes, together with two vital buffer overflow vulnerabilities in WebGL and Daybreak.

 Strengthen Your SOC by Accelerating Menace Detection & Fast Investigations. -> Integrate ANY.RUN With Your SOC Now.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *