Executive brief
Google Chrome for Android contains a use-after-free memory safety defect in its mobile rendering component that allows an attacker to bypass the browser's web origin policy—a critical security boundary that isolates websites from each other. An attacker could exploit this vulnerability by tricking users into visiting a malicious website, potentially allowing unauthorized access to data from other visited websites or injection of malicious content.
Technical details
CVE-2026-85044 is a use-of-released-resource (use-after-free) vulnerability in the Mobile component of Google Chrome on Android. The vulnerability exists in Chrome versions prior to 152.0.7977.82 and allows a remote attacker to bypass the same-origin policy through a crafted HTML page, requiring social engineering to deliver the payload. The attack is network-accessible and does not require user authentication, though it does require user interaction (visiting a malicious page). Exploitation could lead to unauthorized access to sensitive data or cross-origin request forgery. The vulnerability was patched in Chrome 152.0.7977.82 released on September 3, 2026.
Affected products
- Google Chrome prior to 152.0.7977.82 on Android
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Chrome 152.0.7977.82 released