Executive brief
A security vulnerability exists in Google Chrome for Android within its graphics rendering engine. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the device. While the impact is limited by the browser's security sandbox, it could still lead to unauthorized access to browser data or further exploitation of the mobile device.
Technical details
A use-after-free (UAF) vulnerability exists in the Skia graphics component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the processing of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by hosting a malicious webpage; if a user visits the page, the attacker can achieve arbitrary code execution within the context of the Chrome sandbox. This vulnerability was addressed in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched