Junglewise Threat Intelligence

CVE-2026-87438: Google Chrome out of bounds write in WebGL on Android

CVE-2026-87438 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome's WebGL graphics engine on Android contained a memory vulnerability that could allow attackers to bypass Chrome's security sandbox and execute malicious code with unrestricted system access. A malicious website visited in Chrome on Android could exploit this flaw to run arbitrary code outside the sandboxed browser environment.

Technical details

An out of bounds write vulnerability exists in the WebGL component of Google Chrome on Android. The vulnerability allows remote code execution outside the security sandbox when a user visits a crafted HTML page. Attack requires only network reachability and user interaction (visiting a malicious website); no authentication is needed. An attacker can write data beyond allocated memory boundaries, potentially overwriting critical execution structures and achieving arbitrary code execution with full system privileges. The vulnerability was fixed in Chrome 153.0.8010.36 for Android and is no longer exploitable in patched versions.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats