CVE-2026-12028
Google · Chrome
A use-after-free vulnerability in the GPU component of Google Chrome for Android could allow a remote attacker to perform a sandbox escape.
Executive summary
A high-severity use-after-free vulnerability in the GPU component of Google Chrome for Android poses a risk of sandbox escape for mobile device users.
Vulnerability
This vulnerability involves a use-after-free error in the GPU component. A remote attacker could trigger this vulnerability by enticing a user to navigate to a crafted HTML page, potentially escaping the browser sandbox after compromising the renderer process.
Business impact
The CVSS score of 8.3 underscores the criticality of this flaw for mobile security. Exploitation on an Android device could result in the compromise of application data, unauthorized access to system resources, or further malicious activity on the mobile device.
Remediation
Immediate Action: Update Google Chrome on all Android devices to version 149.0.7827.115 via the Google Play Store as soon as the update is available.
Proactive Monitoring: Ensure mobile device management (MDM) policies are in place to track and enforce application version compliance across the mobile fleet.
Compensating Controls: Advise users to avoid clicking on untrusted links and ensure that the "Safe Browsing" feature is enabled within the Chrome settings.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Administrators should prioritize the deployment of the latest Chrome version on all managed Android devices. Ensuring mobile browser security is critical to defending against modern web-based threats.