CVE-2026-19154
Google · Chrome
A use after free vulnerability in the Skia graphics library within Google Chrome on Android allows for potential remote code execution.
Executive summary
A use after free vulnerability in the Skia graphics library on Android-based Google Chrome installations presents a critical risk of remote code execution, necessitating an immediate update.
Vulnerability
This is a use after free vulnerability (CWE-416) in the Skia library, which handles graphics rendering. The flaw can be triggered remotely without authentication, provided the user interacts with malicious content.
Business impact
Exploitation of this vulnerability on mobile devices can result in full device compromise, potentially exposing sensitive corporate data or credentials stored on the Android device. With a CVSS score of 8.3, this is a high-impact vulnerability that could severely affect mobile device fleet security.
Remediation
Immediate Action: Update the Google Chrome application on all Android devices to version 151.0.7922.109 or later through the Google Play Store.
Proactive Monitoring: Monitor mobile device management (MDM) platforms to ensure that all corporate-managed devices have successfully received and applied the latest application updates.
Compensating Controls: Employ mobile threat defense (MTD) solutions that can detect malicious mobile applications or web-based threats that attempt to exploit browser-based vulnerabilities.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Mobile devices are frequently overlooked in patch management cycles, yet they remain critical entry points for attackers. Administrators must ensure that the update is pushed to all mobile endpoints to mitigate the risk of remote code execution via the Skia library.