Junglewise Threat Intelligence

CVE-2026-10892: Google Chrome for Android out of bounds write in GPU

CVE-2026-10892 · Severity: info · CVSS 9.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A critical vulnerability in the browser's graphics processing component could allow a malicious website to bypass security protections (the sandbox) that normally keep web content isolated from the rest of the device. If exploited, this could allow an attacker to gain unauthorized access to the device or sensitive user data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the GPU component of Google Chrome for Android prior to version 149.0.7827.53. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory corruption within the GPU process. A remote, unauthenticated attacker can exploit this to escape the Chrome sandbox and execute arbitrary code with elevated privileges on the underlying Android system. Google has addressed this issue in the stable channel update for version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-05-14: disclosed: Reported by Google internal researchers
  • 2026-06-02: patched: Fixed in Chrome 149.0.7827.53 stable channel update
  • 2026-06-04: advisory: NVD publication date

References

Related threats