Executive brief
A security vulnerability in Google Chrome for Android could allow a malicious website to bypass the browser's security sandbox. This occurs when the browser's graphics processing component (GPU) incorrectly handles memory, potentially allowing an attacker who has already compromised a web page's rendering process to gain broader access to the device. Exploitation typically requires a user to visit a specially crafted, malicious website.
Technical details
A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome on Android. The flaw is triggered when the GPU process improperly manages memory objects, allowing an attacker who has already compromised the renderer process to execute arbitrary code outside of the browser's sandbox. This is achieved by enticing a user to visit a malicious HTML page. The vulnerability was addressed in version 150.0.7871.125.
Affected products
- Google Space Chrome prior to 150.0.7871.125
Timeline
- 2026-06-18: disclosed: Reported to Chrome by Google researchers
- 2026-07-14: patched: Fixed in stable channel update 150.0.7871.125
- 2026-07-14: advisory