CVE-2026-17727

Google · Chrome

An out of bounds write vulnerability in WebGL for Google Chrome on Android permits remote attackers to escape the browser sandbox via a crafted HTML page.

Executive summary

A critical out of bounds write vulnerability in WebGL for Google Chrome on Android provides a pathway for remote attackers to achieve sandbox escape.

Vulnerability

This is an out of bounds write vulnerability located in the WebGL component. An unauthenticated remote attacker can trigger this flaw via a crafted HTML page to perform a sandbox escape.

Business impact

The CVSS score of 9.6 underscores the critical nature of this vulnerability. Successful exploitation grants an attacker the ability to bypass security isolation, which may lead to arbitrary code execution, unauthorized data access, and compromise of the underlying operating system.

Remediation

Immediate Action: Update Google Chrome on Android to version 151.0.7922.72 to remediate this vulnerability.

Proactive Monitoring: Monitor for unexpected application crashes and investigate any reports of abnormal browser behavior that might suggest memory corruption.

Compensating Controls: Implement browser-based security policies where possible to limit the execution of untrusted scripts or WebGL content.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical severity and the potential for total system compromise, immediate patching is mandatory. Organizations must verify that all instances of Google Chrome on Android are updated to version 151.0.7922.72 to secure the environment.