Executive brief
Google Chrome on Android contains an improper input validation flaw in its GPU component that allows an attacker to execute arbitrary code outside the browser's security sandbox. An attacker who has already compromised Chrome's renderer process could exploit this vulnerability to run malicious code with elevated privileges, potentially gaining full device access and stealing sensitive user data.
Technical details
This vulnerability is an improper input validation flaw in the GPU component of Google Chrome on Android (versions prior to 152.0.7977.65). The vulnerability requires an attacker to have already compromised the renderer process; exploitation is triggered via a crafted HTML page. The flaw allows an attacker to bypass the Chrome sandbox and execute arbitrary code outside of it. This is a post-renderer-compromise vulnerability that elevates attack impact from renderer-level to system-level code execution. The vulnerability has been patched in Chrome 152.0.7977.65 and later releases.
Affected products
- Google Chrome before 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65