Junglewise Threat Intelligence

CVE-2026-10953: Google Chrome for Android use after free in Core

CVE-2026-10953 · Severity: info · CVSS 8.8 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the browser's core components could allow a malicious website to bypass security protections (the 'sandbox') that normally keep web content isolated from the rest of the device. If exploited, this could allow an attacker to gain unauthorized access to the device or user data after they have already compromised the initial web-rendering layer.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Core' component of Google Chrome on Android. The flaw is triggered when the browser incorrectly manages memory during the processing of specially crafted HTML content. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this UAF to escape the sandbox and execute arbitrary code with higher privileges on the Android system. This vulnerability was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats