Junglewise Threat Intelligence

CVE-2026-9876: Google Chrome WebGL use after free sandbox escape

CVE-2026-9876 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is a widely used mobile web browser. A critical security vulnerability in its graphics component could allow a malicious website to bypass the browser's security 'sandbox.' If exploited, this could allow an attacker to gain unauthorized access to the underlying mobile operating system or user data.

Technical details

A use-after-free (CWE-416) vulnerability exists in the WebGL component of Google Chrome on Android. The flaw is triggered when the browser incorrectly manages memory during the rendering of 3D graphics. A remote attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing the attacker to execute code outside of the browser's restricted environment. The issue is resolved in version 148.0.7778.216 and later.

Affected products

  • Google Chrome Prior to 148.0.7778.216

Timeline

  • 2026-03-18: other: Reported by researcher happy2me
  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats