Junglewise Threat Intelligence

CVE-2026-6920: Google Chrome out of bounds read in GPU

CVE-2026-6920 · Severity: critical · CVSS 9.6 · Published 2026-04-23

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome on Android could allow a malicious website to bypass the browser's security sandbox. This occurs when a user visits a specially crafted webpage, potentially allowing an attacker who has already gained limited control of the browser to escalate their access. Such an exploit could lead to unauthorized access to device data or broader system compromise.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the GPU component of Google Chrome for Android. The flaw is reachable by a remote attacker who has already compromised the renderer process, typically via a malicious HTML page. By exploiting this memory corruption issue, the attacker can potentially achieve a sandbox escape, gaining elevated privileges on the underlying Android operating system. The vulnerability is addressed in Chrome version 147.0.7727.117 and later.

Affected products

  • Google Chrome prior to 147.0.7727.117

Timeline

  • 2026-04-06: other: Reported by tatiwari of Microsoft
  • 2026-04-22: patched: Stable channel update released
  • 2026-04-23: advisory: NVD publication date

References