Junglewise Threat Intelligence

CVE-2026-11082: Google Chrome for Android race condition in GPU sandbox escape

CVE-2026-11082 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome on Android could allow a malicious website to break out of the browser's security sandbox. This sandbox is designed to isolate web pages from the rest of the device to protect user data and system integrity. If exploited, an attacker who has already gained a foothold in the browser's rendering engine could potentially gain broader access to the underlying Android operating system.

Technical details

A race condition exists within the GPU component of Google Chrome on Android. The vulnerability is classified as a Use-After-Free (CWE-416) resulting from improper synchronization. An attacker must first compromise the renderer process (typically via a separate vulnerability) and then entice a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass the Chrome sandbox, potentially leading to arbitrary code execution with the privileges of the GPU process. This issue was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11082 published.

References

Related threats