Executive brief
Google Chrome on Android contains a memory safety vulnerability in its graphics rendering engine (Dawn) that allows attackers to execute arbitrary code outside the browser sandbox. An attacker can exploit this flaw by crafting a malicious HTML page; if a user visits the page, the attacker gains the ability to run code with the same privileges as the browser, potentially compromising user data and device security.
Technical details
This is a use-after-free vulnerability in the Dawn graphics engine component of Google Chrome on Android prior to version 153.0.8010.52. The vulnerability allows a remote attacker to execute arbitrary code outside the sandbox boundary via a crafted HTML page. No user interaction beyond visiting a malicious page is required. The vulnerability was reported by Florian Schweitzer on April 8, 2026, and patched in Chrome 153.0.8010.52 released September 17, 2026. No public exploit has been reported.
Affected products
- Google Chrome prior to 153.0.8010.52 on Android
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Chrome 153.0.8010.52