Junglewise Threat Intelligence

CVE-2026-87488: Google Chrome use-after-free in WebGL on Android

CVE-2026-87488 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Technologies: Google Chrome, Google Android. Vendors: Google.

Executive brief

Google Chrome on Android contains a memory safety vulnerability in its WebGL graphics component that allows an attacker to execute malicious code outside Chrome's security sandbox. An attacker can exploit this by crafting a malicious webpage that, when visited by a user, gains the ability to run arbitrary code with elevated privileges—potentially compromising user data, installing malware, or taking over the device.

Technical details

The vulnerability is a use-after-free condition in the WebGL component of Google Chrome on Android. It occurs when WebGL code attempts to access memory that has already been freed, allowing an attacker to overwrite freed memory with malicious content. The attack is triggered via a crafted HTML page sent over the network; no user authentication or privilege escalation is required beyond visiting a hostile website. Successful exploitation allows arbitrary code execution outside the browser sandbox, which is critical because it bypasses Chrome's primary defense mechanism. The vulnerability was fixed in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed: Published in NVD and Chrome Security update
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats