Critical WebGL bug lets Chrome run code outside sandbox
CVE-2026-87464 is a use-after-free fixed in Chrome 153.0.8010.36; unpatched Chromium builds, including Debian’s, remain exposed.
A use-after-free in WebGL allowed a remote attacker to execute arbitrary code outside the Chromium sandbox via a crafted HTML page, according to the NIST advisory for CVE-2026-87464.
Google rated the issue Critical and fixed it in Chrome 153.0.8010.36. The same flaw sits in the shared Chromium codebase, so it affects Chromium and browsers built from it. Debian’s security tracker still lists all current Chromium packages as vulnerable.
Further technical detail is unavailable because the related Chromium issue is restricted. A linked fix went into ANGLE, the graphics stack Chromium uses for WebGL. Valtteri Vuorikoski summarized the public record on the oss-security list.