Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the printing component could allow a malicious website to bypass security protections that normally isolate web pages from the rest of the device. If exploited, an attacker who has already gained some control over the browser's rendering process could potentially access sensitive data or execute unauthorized commands outside of the browser's restricted environment.
Technical details
A use-after-free (UAF) vulnerability exists in the Printing component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during printing operations, allowing a remote attacker to exploit the memory corruption via a specially crafted HTML page. To achieve a sandbox escape, the attacker must first have compromised the renderer process. This vulnerability is tracked as CWE-416 and was addressed in version 149.0.7827.103.
Affected products
- Google Chrome prior to 149.0.7827.103
Timeline
- 2026-04-13: disclosed: Reported by Google researchers
- 2026-06-08: patched: Stable channel update released
- 2026-06-09: advisory: NVD publication date