Junglewise Threat Intelligence

CVE-2026-84352: Google Chrome WebGL use-after-free on Android

CVE-2026-84352 · Severity: critical · CVSS 9.6 · Published 2026-09-02

Technologies: Google Android, Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android contains a memory safety vulnerability in its WebGL graphics component that allows attackers to bypass the browser's security sandbox. An attacker can craft a malicious web page that, when visited, executes arbitrary code with the browser's full privileges, potentially compromising user data and device security.

Technical details

A use-after-free vulnerability exists in the WebGL implementation of Google Chrome on Android versions prior to 152.0.7977.75. The vulnerability allows remote attackers to execute arbitrary code outside the sandbox by delivering a crafted HTML page to a user. This is a memory corruption flaw where freed memory is accessed after deallocation, enabling code execution. No user interaction beyond visiting a webpage is required. The vulnerability was patched in Chrome version 152.0.7977.75 and later.

Affected products

  • Google Chrome prior to 152.0.7977.75 on Android

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in Chrome 152.0.7977.75

References

Related threats