CVE-2026-17726

Google · Chrome

An integer overflow vulnerability in WebGL within Google Chrome on Android enables remote attackers to perform a sandbox escape through a specially crafted HTML page.

Executive summary

A critical integer overflow flaw in WebGL for Google Chrome on Android allows remote attackers to bypass sandbox security and execute arbitrary code.

Vulnerability

This vulnerability involves an integer overflow in the WebGL implementation. An unauthenticated remote attacker can leverage this flaw to escape the browser sandbox when a user renders a malicious HTML page.

Business impact

With a CVSS score of 9.6, this vulnerability is classified as critical. Exploitation allows an attacker to break out of the browser sandbox, which could result in full device control, unauthorized access to local storage, and the execution of malicious payloads with elevated privileges.

Remediation

Immediate Action: Apply the update to Google Chrome version 151.0.7922.72 across all affected Android devices.

Proactive Monitoring: Review security logs for indicators of WebGL-related errors or memory corruption patterns.

Compensating Controls: Utilize enterprise mobile device management solutions to enforce browser updates and restrict access to high-risk web content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability is highly severe and requires immediate attention to prevent potential exploitation. Organizations should ensure all managed devices receive the patch to version 151.0.7922.72 as soon as possible.