Executive brief
Google Chrome on Android contains a memory safety vulnerability in its WebGL graphics component that allows attackers to bypass the browser's security sandbox. An attacker can craft a malicious web page that, when visited, executes arbitrary code with the browser's full privileges, potentially compromising user data and device security.
Technical details
A use-after-free vulnerability exists in the WebGL implementation of Google Chrome on Android versions prior to 152.0.7977.75. The vulnerability allows remote attackers to execute arbitrary code outside the sandbox by delivering a crafted HTML page to a user. This is a memory corruption flaw where freed memory is accessed after deallocation, enabling code execution. No user interaction beyond visiting a webpage is required. The vulnerability was patched in Chrome version 152.0.7977.75 and later.
Affected products
- Google Chrome prior to 152.0.7977.75 on Android
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Chrome 152.0.7977.75