CVE-2026-3537
8.8Google · Chrome
A heap corruption vulnerability exists in the PowerVR component of Google Chrome on Android, allowing remote attackers to trigger memory issues via crafted HTML pages.
Executive summary
Google Chrome on Android contains a critical object lifecycle vulnerability in the PowerVR component that could allow a remote attacker to achieve heap corruption.
Vulnerability
This is an object lifecycle issue within the PowerVR graphics driver component. An unauthenticated remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page, leading to heap corruption.
Business impact
The exploitation of this vulnerability can result in significant security compromise, including potential remote code execution or application instability. Given the CVSS score of 8.8, this represents a High severity risk that could lead to full system compromise of the affected mobile device. Organizations relying on Chrome for Android in enterprise environments face potential data leakage and unauthorized access to sensitive user information if these devices are targeted.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 145.0.7632.159 or later immediately.
Proactive Monitoring: Monitor mobile device management (MDM) logs for browser version compliance and investigate any reports of abnormal browser crashes or unexpected behavior on mobile endpoints.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to provide an additional layer of detection against malicious web content.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this heap corruption flaw necessitates an immediate update to the latest stable release of Google Chrome for Android. Security administrators should prioritize the deployment of this update via MDM solutions to ensure that all corporate-managed devices are protected against potential remote exploitation.