Junglewise Threat Intelligence

CVE-2026-87643: Google Chrome integer overflow in GPU on Android

CVE-2026-87643 · Severity: critical · CVSS 9.6 · Published 2026-09-09

Executive brief

Google Chrome on Android contains an integer overflow vulnerability in the GPU component that allows attackers to execute arbitrary code outside the browser's security sandbox. An attacker can exploit this by hosting a malicious web page and tricking a user into visiting it, potentially gaining full control over the device and accessing sensitive data.

Technical details

An integer overflow vulnerability exists in the GPU component of Google Chrome on Android prior to version 153.0.8010.36. The vulnerability is triggered when processing crafted HTML content, allowing a remote attacker to escape the sandbox and execute arbitrary code. The attack requires user interaction (visiting a malicious webpage) but no authentication. The vulnerability was fixed in Chrome 153.0.8010.36. Chromium classified this as Medium severity, though the reported CVSS score is 9.6.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed: CVE-2026-87643 public disclosure
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats