Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve-2026-13934 — Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and security lessons. | Kitploit
Tools/GitHubGitHub/artwiderobo/cve-2026-13934
Vulnerability AnalysisCode AnalysisExploitationWeb SecurityPapers & ResearchLearning & Education
GitHubartwiderobo/cve-2026-13934

cve-2026-13934

Structured vulnerability research repo for a Chrome Dawn WebGPU CWE-20 flaw: root cause, patch diff, static verification, severity review, and security lessons.

View Repository
161 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-13934

This is the work project repository. Investigation, analysis, work, and reports are handled in one repo (D088/D091).

This file is the repository/board entry document. For the full folder and artifact conventions, see docs/conventions.md. The body (status, conclusions, links) is updated when a report item is promoted. Investigation, analysis, and work agents do not modify the root README.

One-line summary: Google Chrome's WebGPU implementation Dawn did not check the parameter constraints required by the Vulkan specification when creating YCbCr samplers, allowing an attacker who already controlled the renderer process to pass specification-violating values through to the GPU process (CWE-20). The fix added validation and backend enforcement as two layers, and was included in Chrome 150.0.7871.47.

Detailed learning documents are in docs/cve-2026-13934/ — written so that the cause, fix, evidence, and lessons can be followed without reproduction.

Status

Target: CVE-2026-13934 — Google Chrome / Dawn (WebGPU implementation), vulnerability type CWE-20 (Improper Input Validation). CVE published 2026-06-30, fixed version 150.0.7871.47. Basis: research/20260804-cve-2026-13934-6bacf7/sources.md §1, §2.

Progress stages — carried out across four tracks: investigation (public information), investigation (patch/diff), analysis (reproduction/demonstration), and reporting (learning summary); all four tracks are complete.

TrackStatusWhat was obtained
Public information and impact scope investigation (research/…-6bacf7/)Complete (4 documents)CVE, NVD, vendor advisory metadata, CWE/CVSS, affected version boundaries, judgment criteria rulings
Patch/diff comparison (research/…-diff-92f928/)Complete (4 documents)Fixing commit identified, three-tier comparison baseline, changed files/logic delta, bypass/residual risk rulings
Reproduction/demonstration (cases/…-4d10a8/)Complete (6 documents) — static comparison performed, no execution-level observationRoot cause structure, exploitability/constraints, static comparison observations of both revisions
Learning report (reports/…-8400bc/)Complete (4 documents)Table of contents/citation map, root README draft, docs/ document list

What has been confirmed

  • CVE identifier and status (public), CNA (Chrome/Google), affected product (Google Chrome), affected component (Dawn).
  • Fixed version 150.0.7871.47, the fixing commit (Dawn 43055cbe…), and the 3 changed files with the reasons for the changes.
  • The vulnerable revision has no specification-constraint validation, enforcement, or regression tests, while the fixed revision has all of them — confirmed by static comparison of the two Dawn snapshots actually pinned by Chrome (cases/20260804-cve-2026-13934-4d10a8/report.md §3).

What has not been confirmed yet (not filled in with speculation)

  • No execution-level observation — we did not build the two revisions and run unit tests. The actual output of the validation error message, the generated VkSampler parameters, and the VUID reports from the Vulkan validation layers are expected values based on the code (cases/…-4d10a8/report.md §4).
  • Affected platform — the CVE description says "on Android", but the vendor advisory carrying this CVE is a desktop channel advisory. Whether the same path holds on desktop was not verified.
  • Affected version boundary — Chromium tags 150.0.7871.46, .47, and .63 all pin the same Dawn revision, yet the CVE says "prior to .47". We could not confirm the basis for this notation.
  • Completeness of the fix — there was one commit on the Dawn side referencing this bug, but whether accompanying changes were made on the Chromium src side was not exhaustively investigated.
  • Vendor internal analysis — Chromium issue 513006636 containing the root cause is access-restricted.

Severity — differs by source. The vendor (Chromium) itself rates it Medium, CISA-ADP's CVSS v3.1 is 9.6 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), and there is no NVD own assessment. Both are stated side by side without ruling which is correct — the interpretation is in docs/cve-2026-13934/overview.md.

This repository has no deployed services (APIs, backends, databases, etc.). All artifacts are documents.

Key conclusions

1. Root cause — the precondition required by the specification was not checked

The Vulkan specification requires that for samplers with YCbCr conversion, the address mode of all axes is CLAMP_TO_EDGE and anisotropic filtering is disabled (VUID-VkSamplerCreateInfo-addressModeU-01646). Before the patch, Dawn did not check this constraint, so specification-violating parameters could pass validation and reach VkSampler creation.

The decisive point is the threat model. The public description assumes an attacker who already controls the renderer process ("a remote attacker who had compromised the renderer process"). From that position, inter-process commands can be manipulated directly rather than going through the normal web API path, so renderer-side validation is outside the trust boundary. And Dawn's Vulkan backend runs in the GPU process, which has higher privileges than the renderer — which is why this flaw becomes a sandbox escape surface.

Basis: cases/20260804-cve-2026-13934-4d10a8/root_cause.md §2 · Details: docs/cve-2026-13934/root-cause-and-fix.md

2. Fix — did not stop at a single layer of validation

The fixing commit is Dawn 43055cbeadddca41a9c973a809f859d641077b2f ("Add YCbCr sampler validation", 2026-05-27, Bug: 513006636) and changes three files.

ChangeFileNature
Adds 4 checks for address mode and maxAnisotropy on YCbCr samplerssrc/dawn/native/Sampler.cppFrontend validation — rejects violating requests
Overwrites address mode and anisotropy with specification-compliant values on paths with YCbCr conversionsrc/dawn/native/vulkan/SamplerVk.cppBackend enforcement — never creates a violating state regardless of input
Adds regression test YCbCrSamplerRequiredParamssrc/dawn/tests/unittests/validation/YCbCrValidationTests.cppPrevents recurrence

This structure is the core of this CVE. Because the renderer is assumed to be already compromised, validation alone is insufficient; the second layer, which enforces values on the higher-privilege side, is the substantive line of defense. Summarizing this as "input validation was missing, so validation was added" misses the point of the defense design.

The change scale is 53 additions, 0 deletions — a patch that fills in the missing checks without modifying existing logic.

Basis: research/20260804-cve-2026-13934-diff-92f928/report.md §3, §4 · cases/20260804-cve-2026-13934-4d10a8/patch_diff.md §4

3. Demonstration — verified to the static level

Download Tool