Junglewise Threat Intelligence

CVE-2026-79241: Google Chrome out of bounds read in GPU on Android

CVE-2026-79241 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome for Android contains a flaw that allows attackers to read memory outside the browser's sandbox through a crafted web page. This could expose sensitive data held in memory, including user credentials, personal information, or browsing data, bypassing Chrome's security protections.

Technical details

This vulnerability is an out-of-bounds read in Chrome's GPU component affecting the Android platform. The flaw allows a remote attacker to read memory outside the browser sandbox by delivering a crafted HTML page to a victim. The attack requires user interaction (visiting a malicious website) but does not require authentication or special privileges. Successful exploitation could disclose sensitive data stored in memory. The vulnerability was patched in Chrome 152.0.7977.65 and later versions for Android.

Affected products

  • Google Chrome prior to 152.0.7977.65 on Android

Timeline

  • 2026-08-25: disclosed: Publicly disclosed as CVE-2026-79241
  • 2026-08-25: patched: Fix included in Chrome 152.0.7977.65 for Android

References

Related threats