Executive brief
Google Chrome on Android contains a use-after-free vulnerability in the Shared Tab Groups feature that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this by tricking a user into visiting a crafted web page, potentially gaining the ability to steal data, install malware, or take full control of the device.
Technical details
A use-after-free vulnerability exists in the Shared Tab Groups feature of Google Chrome on Android versions prior to 152.0.7977.75. The vulnerability stems from improper memory management in the Tab Groups component, allowing an attacker to access memory that has been freed, leading to code execution outside the sandbox. The attack requires user interaction (clicking a malicious link or visiting a crafted HTML page) but does not require authentication. Successful exploitation allows arbitrary code execution with privileges outside the sandbox, potentially giving the attacker access to the entire device. The vulnerability was fixed in Chrome 152.0.7977.75 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.75 on Android
Timeline
- 2026-09-02: disclosed: CVE-2026-84353 published