CVE-2026-15900
Google · Chrome
A critical use-after-free vulnerability in the GPU component of Google Chrome on Android allows remote attackers to trigger a sandbox escape via a crafted HTML page.
Executive summary
A critical use-after-free vulnerability in the Google Chrome GPU component on Android allows for potential remote sandbox escape, posing a significant risk to mobile device security.
Vulnerability
This is a use-after-free memory corruption flaw located in the GPU component of the browser. The vulnerability is triggered when an unauthenticated user visits a specially crafted HTML page, leading to a potential sandbox escape.
Business impact
The CVSS score of 9.6 indicates a critical severity level, reflecting the potential for full system compromise if the sandbox is successfully escaped. Such an exploit could allow attackers to bypass OS-level protections, resulting in unauthorized data access, the installation of malicious software, or total device takeover. Organizations relying on Android devices for mobile productivity should prioritize this update to prevent potential lateral movement or data exfiltration.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 150.0.7871.128 or later.
Proactive Monitoring: Review mobile device management logs for anomalous application behavior or unexpected crashes associated with the Chrome browser.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to assist in detecting and blocking malicious applications that may attempt to exploit such vulnerabilities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS score and the potential for a sandbox escape, organizations must treat this vulnerability with high urgency. Administrators should push the latest version of Google Chrome to all managed Android endpoints immediately to mitigate the risk of remote code execution and sandbox compromise.