Executive brief
A critical vulnerability exists in the Google Chrome browser for Android within its WebGL component, which handles 3D graphics. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying mobile operating system and sensitive user data.
Technical details
A use-after-free (UAF) vulnerability exists in the WebGL component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory for graphics objects, allowing an attacker to reference memory after it has been freed. By enticing a user to visit a malicious website containing a crafted HTML page, a remote attacker can exploit this memory corruption to execute arbitrary code and escape the Chrome renderer sandbox. This vulnerability is mitigated by updating to version 149.0.7827.197 or later.
Affected products
- Google Chrome prior to 149.0.7827.197
Timeline
- 2026-06-13: disclosed: Reported by Google internal researchers
- 2026-06-23: patched: Stable channel update released
- 2026-06-24: advisory: NVD publication date