CVE-2026-11012

Google · Chrome on Android

A use-after-free vulnerability in the Serial component of Google Chrome on Android allows for potential remote code execution.

Executive summary

A high-severity use-after-free vulnerability in the Google Chrome on Android Serial component poses a significant risk for arbitrary code execution.

Vulnerability

This use-after-free vulnerability exists in the Serial component of the browser. By triggering this memory corruption flaw, an attacker could potentially execute arbitrary code, compromising the security of the browser and the underlying Android device.

Business impact

The CVSS score of 8.3 highlights the substantial risk of this vulnerability. Exploitation could allow an attacker to bypass security boundaries, potentially resulting in unauthorized access to sensitive information or the installation of malicious software on the affected device.

Remediation

Immediate Action: Update the Google Chrome application to the latest version via the Google Play Store to patch the identified memory corruption issue.

Proactive Monitoring: Review device logs for anomalous application behavior and ensure that security patches are applied promptly upon release.

Compensating Controls: Maintain updated security software on mobile devices and exercise caution when granting serial device access permissions to websites.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Users and administrators must ensure all Chrome installations on Android are updated immediately. Given the severity of use-after-free vulnerabilities, keeping software current is the most effective defense against potential exploitation of this flaw.