ConicPlex

Start Your Project

A laptop glowing with colorful abstract graphics light on a wooden desk at dusk, evoking browser GPU rendering security

On this Page

Chrome Patches Two Critical Vulnerabilities in WebGL and Dawn (CVE-2026-76034, CVE-2026-76036)

Chrome 151.0.7922.169 patches 15 security issues, including two critical bugs in WebGL and Dawn (WebGPU). Here is what changed and who needs to check.

Sameer Malek

August 20, 2026

Google shipped a Chrome stable channel update on August 18, 2026, patching 15 security issues, two of them rated critical. CVE-2026-76034 is a buffer overflow in WebGL. CVE-2026-76036 is a buffer overflow in Dawn, the library that implements WebGPU. Both could let an attacker run code outside Chrome’s sandbox from a page that loads crafted WebGL or WebGPU content. The fix is in Chrome 151.0.7922.169/.170 for Windows and Mac and 151.0.7922.169 for Linux, rolling out over the coming days.

What Else Got Patched

The other 13 fixes are rated high severity. A few stand out. CVE-2026-76038 is a type confusion bug in V8, Chrome’s JavaScript engine, reported August 3. CVE-2026-76045 is a use-after-free in WebGL found by OpenAI Codex Security, an automated bug-hunting system, on August 5. There’s also a second V8 type confusion issue (CVE-2026-76047) and an information leak in Skia, Chrome’s graphics library (CVE-2026-76041). Google’s release notes list all 15 with links to the underlying Chromium issue tracker entries, though some details stay restricted until most users have updated.

Who Needs to Act

Chrome updates itself in the background for most people, so a restart is usually all it takes. Where this matters more is anywhere Chrome runs unattended or gets updated on a slower cycle: managed fleets, kiosk or embedded browser deployments, and CI environments that run headless Chrome for testing or scraping. Those setups don’t restart on their own and are worth checking manually.

The WebGL and Dawn fixes are also worth a second look if a site leans on canvas-heavy interactive work: a 3D product configurator, a WebGL-driven landing page animation, or anything built with Three.js or a similar rendering library. None of that code caused the bug, but it’s the kind of experience that touches the same rendering paths, so a quick smoke test after updating is cheap insurance. This is the same rendering layer our Web Application Development team checks whenever a browser ships a security release mid-project.

Sources

Sameer Malek is a Senior Full Stack Developer at ConicPlex, working across the stack on projects that don’t fit neatly into one platform or framework. He’s often the person weighing a genuine platform or architecture decision rather than defending one side of it, since his work regularly crosses between WordPress, custom builds, and everything in between. He writes here about the comparisons and tradeoffs that come up when there’s more than one reasonable way to build something.

Keep reading

News & Updates

A laptop on a wood desk with a glowing multicolor magnifying glass hovering over stacked browser-window cards, symbolizing a Google search ranking update

Google’s August 2026 Spam Update Is Rolling Out Worldwide

Google began rolling out its third spam update of 2026 on August 18, applying globally across every language. Here is…

Sameer Malek

August 20, 2026

News & Updates

A laptop on a real desk at night glowing with a blurred grid of file thumbnails, evoking a WordPress file upload

Elementor Pro Patches a Critical Unauthenticated File Upload Flaw (CVE-2026-32475)

Elementor Pro 4.2.2 patches CVE-2026-32475, a CVSS 9.0 unauthenticated file upload flaw in the Form widget that let attackers plant…

Aftab Memon

August 20, 2026

News & Updates

A hand sliding a folder into an open metal filing cabinet drawer among rows of archived paper files, illustrating an unauthorized file being written into an existing directory

W3 Total Cache Patches a Critical Unauthenticated File-Write Bug (CVE-2026-18051)

W3 Total Cache before 2.10.5 has a critical unauthenticated file-write flaw, CVE-2026-18051, CVSS 10.0. Update now….

Aftab Memon

August 20, 2026