Junglewise Threat Intelligence

CVE-2026-12010: Google Chrome heap buffer overflow in GPU

CVE-2026-12010 · Severity: info · CVSS 9.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for Android that could allow an attacker to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted website, an attacker who has already compromised the browser's rendering process could gain deeper access to the underlying operating system. This could lead to unauthorized data access or full control over the affected mobile device.

Technical details

A heap buffer overflow vulnerability (CWE-122) exists in the GPU component of Google Chrome for Android. The flaw can be triggered by a remote attacker who has already achieved code execution within the sandboxed renderer process. By utilizing a specially crafted HTML page, the attacker can exploit this overflow to escape the Chrome sandbox and execute arbitrary code with elevated privileges on the host Android system. This vulnerability was addressed in version 149.0.7827.115.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-28: disclosed: Reported to Chromium project by Google researchers
  • 2026-06-11: patched: Fixed in stable channel update 149.0.7827.115
  • 2026-06-11: advisory

References

Related threats