Junglewise Threat Intelligence

CVE-2026-17727: Google Chrome for Android out of bounds write in WebGL

CVE-2026-17727 · Severity: info · CVSS 8.8 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to break out of the browser's security sandbox. This component is responsible for rendering 3D graphics within the browser. If exploited, an attacker could potentially gain unauthorized access to the underlying mobile operating system and user data.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the WebGL implementation of Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to write data outside the intended buffer boundaries. This memory corruption can be leveraged to achieve a sandbox escape, bypassing the security boundaries that isolate the browser process from the rest of the Android operating system. The issue is resolved in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats