CVE-2026-16419
Google · Chrome
An out of bounds read and write in ANGLE in Google Chrome on Android allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Executive summary
A critical out of bounds read and write vulnerability in Google Chrome on Android could allow remote attackers to escape the sandbox and execute arbitrary code.
Vulnerability
This vulnerability affects the ANGLE graphics abstraction layer and is triggered when a user navigates to a specially crafted HTML page. It is an unauthenticated, remote-reachable flaw that impacts the browser's memory safety.
Business impact
The ability to perform a remote sandbox escape on mobile devices creates a significant risk of data exfiltration and unauthorized code execution. Given the CVSS score of 9.6, this is a critical vulnerability that could lead to complete compromise of the affected Android device, exposing corporate credentials or internal communications.
Remediation
Immediate Action: Update Google Chrome on all Android devices to version 150.0.7871.182 or later through the Google Play Store.
Proactive Monitoring: Monitor mobile device management (MDM) logs to identify devices running outdated browser versions and alert on suspicious web-based activity.
Compensating Controls: Utilize mobile security solutions that block malicious URLs and provide real-time protection against browser-based exploits.
Exploitation status
Public Exploit Available: No (unknown).
Analyst recommendation
The critical severity of this vulnerability necessitates immediate patching. Organizations should enforce version updates via MDM policies to ensure all Android devices are protected against potential remote code execution attacks.