Executive brief
Google Chrome on Android contains a memory safety bug in its graphics rendering engine (Dawn) that allows attackers to run malicious code outside the security sandbox by tricking users into visiting a specially crafted website. This bypass of Chrome's sandbox protection could lead to complete compromise of the device and access to sensitive user data.
Technical details
A use-after-free vulnerability exists in the Dawn graphics library component of Google Chrome on Android prior to version 152.0.7977.75. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox via a maliciously crafted HTML page. The attack requires user interaction (visiting a malicious website) but no authentication. Successful exploitation results in arbitrary code execution with the privileges of the Chrome process, bypassing the sandbox isolation. Google has patched this issue in Chrome version 152.0.7977.75 and later.
Affected products
- Google Chrome prior to 152.0.7977.75 on Android
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: patched in Chrome 152.0.7977.75