Junglewise Threat Intelligence

CVE-2026-9875: Google Chrome WebGL out-of-bounds read sandbox escape

CVE-2026-9875 · Severity: info · CVSS 9.8 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for Android's WebGL component, which handles 3D graphics in the browser. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying mobile operating system, potentially leading to the theft of sensitive data or full device compromise.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the WebGL implementation of Google Chrome for Android. The flaw is triggered when the browser processes a maliciously crafted HTML page containing specific WebGL instructions. This memory safety issue allows a remote attacker to read data outside of intended buffers, which can be leveraged to bypass the Chromium sandbox. Successful exploitation grants the attacker the ability to execute code outside of the restricted browser environment on the host Android system. The vulnerability is addressed in version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-04-29: other: Reported by anonymous researcher
  • 2026-05-27: patched: Fixed in version 148.0.7778.216/217
  • 2026-05-28: disclosed: Public advisory released

References

Related threats