OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-95349

CRITICAL · CVSS 9.6 EPSS 0.51%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical buffer overflow vulnerability in WebGL within Google Chrome on Android prior to version 154.0.8037.57 allows remote attackers to execute arbitrary code outside the sandbox by leveraging a specially crafted HTML page. This flaw poses a significant risk to users of affected Android devices and should be prioritized by organizations managing Android applications and services that utilize Chrome for rendering content. Immediate updates to the latest version of Chrome are essential to mitigate potential exploitation.

CVE
CVE-2026-95349
Severity
CRITICAL
CVSS
9.6
EPSS
0.51%
Android Chrome

Original NVD Description

Buffer overflow in WebGL in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Related CVEs

Other vulnerabilities affecting the same vendor(s)