CVE-2026-19137
Google · Chrome
A use after free vulnerability in the WebGL implementation of Google Chrome on Android allows a remote attacker to execute arbitrary code.
Executive summary
A high-severity use after free vulnerability in WebGL on Android-based Google Chrome could lead to arbitrary code execution.
Vulnerability
This is a use after free vulnerability (CWE-416) located in the WebGL graphics component. The flaw is accessible to unauthenticated attackers via user interaction with malicious web content.
Business impact
Exploitation of this vulnerability poses a severe risk to mobile devices running Chrome on Android. Successful attacks can result in unauthorized code execution, potentially bypassing platform security controls. With a CVSS score of 8.3, this flaw is a significant concern for mobile device management and security policies.
Remediation
Immediate Action: Update the Google Chrome application on all Android devices to the latest version via the Google Play Store or managed update channels.
Proactive Monitoring: Review mobile device management logs for outdated application versions and enforce update compliance policies.
Compensating Controls: Implement mobile threat defense solutions that can detect and block malicious web traffic before it interacts with browser components.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should ensure that all Android devices are running the latest version of Google Chrome. Given the ubiquity of mobile browsing, failing to address this vulnerability increases the risk of device-level compromise and data theft.