Executive brief
Google Chrome for Android contains a memory access vulnerability in the Tint graphics component that could allow an attacker to read sensitive data from the browser's sandboxed memory. An attacker can exploit this by hosting a malicious web page that a user visits, potentially exposing user data or system information without requiring any special user permissions beyond visiting a website.
Technical details
This vulnerability is an out-of-bounds read flaw in the Tint component of Google Chrome on Android. The vulnerability allows a remote attacker to read memory within the browser's sandbox by hosting a crafted HTML page. The attack requires only network connectivity and user interaction (visiting a malicious website); no authentication is needed. An attacker can read arbitrary memory contents within the sandbox context, potentially exposing sensitive information such as authentication tokens, user data, or other in-memory secrets. The vulnerability was fixed in Chrome 152.0.7977.65 for Android, and users should update immediately to obtain the patch.
Affected products
- Google Chrome prior to 152.0.7977.65 on Android
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65