CVE-2026-19141

Google · Chrome

A use after free vulnerability in the Resources component of Google Chrome on Android allows for potential arbitrary code execution.

Executive summary

A high-severity use after free vulnerability in Google Chrome on Android could allow a remote attacker to execute arbitrary code on the affected mobile device.

Vulnerability

This vulnerability involves a use after free condition within the Resources component of Google Chrome on Android. The attack requires user interaction and is exploitable by an unauthenticated remote attacker.

Business impact

Exploitation of this vulnerability poses a severe risk to mobile devices used within the enterprise, potentially leading to full compromise of the device. With a CVSS score of 8.3, the vulnerability is classified as high-risk, necessitating prompt attention to prevent unauthorized access to sensitive corporate data stored on or accessed via mobile platforms.

Remediation

Immediate Action: Update Google Chrome on all Android devices to version 151.0.7922.109 or later via the Google Play Store.

Proactive Monitoring: Monitor mobile device management (MDM) reports to ensure all fleet devices have successfully updated to the patched version.

Compensating Controls: Utilize mobile threat defense solutions to detect malicious application behavior or abnormal network traffic that may indicate exploitation attempts.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the prevalence of mobile devices in modern workflows, the urgency of this update is high. Organizations must ensure that users are prompted or forced to update their mobile browsers to the latest version to mitigate this risk.