Junglewise Threat Intelligence

CVE-2026-9943: Google Chrome WebGL out of bounds read on Android

CVE-2026-9943 · Severity: info · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites you have open. This occurs within the WebGL component, which handles 3D graphics in the browser. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information across different browser tabs.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the WebGL component of Google Chrome on Android. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read memory outside of the intended buffer. This can be leveraged to bypass cross-origin resource sharing (CORS) protections and leak sensitive data from other origins. The vulnerability is addressed in version 148.0.7778.216 and later. The attack requires no special privileges other than the ability to convince a user to navigate to a malicious URL.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released for desktop and Android versions.
  • 2026-05-28: disclosed: CVE published to the NVD.

References

Related threats