Executive brief
Google Chrome on Android contains a memory safety vulnerability in its Dawn graphics component that allows attackers to execute arbitrary code outside the browser sandbox by tricking users into visiting a malicious website. Successful exploitation could give attackers full control over the device, including access to all user data and applications.
Technical details
A use-after-free vulnerability exists in the Dawn graphics component of Google Chrome on Android prior to version 153.0.8010.36. The vulnerability allows remote attackers to escape the browser sandbox and execute arbitrary code by supplying a crafted HTML page containing malicious graphics rendering instructions. No special user privileges or authentication are required; victims need only visit a malicious website. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36 on Android
Timeline
- 2026-09-09: disclosed: CVE-2026-87520 published on NVD
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36