Executive brief
Google Chrome on Android is a widely used mobile web browser. A critical security vulnerability in its graphics component could allow a malicious website to bypass the browser's security 'sandbox.' If exploited, this could allow an attacker to gain unauthorized access to the underlying mobile operating system or user data.
Technical details
A use-after-free (CWE-416) vulnerability exists in the WebGL component of Google Chrome on Android. The flaw is triggered when the browser incorrectly manages memory during the rendering of 3D graphics. A remote attacker can exploit this by enticing a user to visit a malicious website containing a crafted HTML page. Successful exploitation could lead to a sandbox escape, allowing the attacker to execute code outside of the browser's restricted environment. The issue is resolved in version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-03-18: other: Reported by researcher happy2me
- 2026-05-27: patched: Stable channel update released
- 2026-05-28: disclosed: NVD publication date