Executive brief
Google Chrome on Android contains a use-after-free vulnerability in its audio processing component that allows an attacker with a compromised renderer process to break out of the browser sandbox and execute arbitrary code. This could enable an attacker to gain full control of the affected device and access sensitive user data, bypassing Chrome's security isolation mechanisms.
Technical details
A use-after-free vulnerability exists in Google Chrome's audio processing code on Android versions prior to 152.0.7977.65. The vulnerability is triggered through a crafted HTML page and requires that an attacker has already compromised the Chrome renderer process. Once triggered, the use-after-free allows arbitrary code execution outside the sandbox boundary, effectively escaping Chrome's security isolation. The vulnerability has been assigned Chromium security severity "Medium" but was reported with a CVSS score of 8.3. A fix is available in Chrome 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65