Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in its graphics rendering component (WebGL) could allow a malicious website to bypass security protections that normally isolate the browser from the rest of the device. If exploited, this could lead to unauthorized access to the user's device or data beyond the browser's intended boundaries.
Technical details
An integer overflow (CWE-190) exists in the WebGL implementation of Google Chrome on Android. The vulnerability is triggered when the browser processes a maliciously crafted HTML page, potentially leading to memory corruption. A remote, unauthenticated attacker can leverage this flaw to achieve a sandbox escape, allowing code execution outside of the restricted browser environment. The issue was addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed