Google has issued an urgent Stable Channel security update for Google Chrome Desktop, resolving 11 security vulnerabilities across core rendering and graphics components. The most severe issue in the batch is CVE-2026-103628, an externally reported Critical-severity out-of-bounds write flaw in WebGL. Exploitation allows specially crafted HTML5 canvas and 3D graphics rendering instructions to corrupt GPU process memory buffers, creating a viable path for remote code execution and escape from the Chromium sandbox.
Anatomy of CVE-2026-103628: WebGL Out-of-Bounds Memory Corruption
WebGL (Web Graphics Library) provides hardware-accelerated 3D graphics inside Chromium by communicating between the untrusted renderer process and the privileged GPU process. To preserve boundary separation, Chromium employs rigorous validation layers within its GPU command buffer parser.
Under CVE-2026-103628, a boundary check breakdown occurs during the compilation and allocation of dynamic vertex attribute arrays. When a web page supplies non-standard buffer stride parameters combined with compressed texture coordinates, the GPU process incorrectly computes memory offsets. Instead of clamping writes to the allocated backing memory segment, the WebGL pipeline writes raw data past the designated boundary (CWE-787: Out-of-bounds Write).
Because this memory corruption occurs directly within the GPU process context, an attacker possessing an initial low-privilege renderer exploit can chain this flaw to corrupt GPU control flow, hijack execution pointers, and break out of the operating system sandbox.
The October 2026 Desktop Fix Rollup
Alongside the critical WebGL defect, Google patched ten additional security issues. The stable rollout contains multiple High-severity bugs across the JavaScript engine and network protocols:
| CVE Identifier | Severity | Vulnerable Component | Flaw Type / Impact |
|---|---|---|---|
| CVE-2026-103628 | Critical | WebGL Subsystem | Out-of-bounds write leading to GPU process memory corruption |
| CVE-2026-103627 | Medium | SVG Graphics Engine | Information disclosure and memory layout leakage |
| High Tier Flaws | High | V8 / FedCM / WebRTC | Type confusion in V8 JIT engine and session validation bypasses |
Defensive Playbook: Enterprise Remediation Checklist
Enterprise IT and security operations teams should enforce immediate automated rollout across managed browser fleets:
- Verify Browser Build: Ensure Linux installations report
154.0.8037.97or later, and Windows/macOS endpoints report154.0.8037.97or154.0.8037.98. - Command-Line Verification (Linux):
google-chrome --version # Expected: Google Chrome 154.0.8037.97 or higher - Group Policy & MDM Enforcement: Configure Chrome Enterprise Core or Intune policies (
RelaunchNotificationset to Required) to prompt users to restart running browser instances within 24 hours. - Temporary WebGL Hardening: For high-assurance isolation zones or PAM jump boxes where 3D graphics are unnecessary, WebGL can be disabled globally via policy:
// Chrome Enterprise Policy: Disable WebGL { "Disable3DAPIs": true }



