CVE-2026-3936
8.8Google · Chrome on Android
A use after free vulnerability in Google Chrome on Android allows remote attackers to trigger heap corruption via a crafted HTML page.
Executive summary
A heap-based use after free vulnerability in Google Chrome on Android presents a significant risk of remote code execution or system instability.
Vulnerability
This is a use after free flaw (CWE-416) within the WebView component that allows an unauthenticated remote attacker to cause heap corruption by enticing a user to visit a malicious HTML page.
Business impact
Successful exploitation of this vulnerability allows a remote attacker to gain control over the affected application process, potentially leading to unauthorized data access or arbitrary code execution. Given the CVSS score of 8.8, this flaw represents a high-severity risk that could compromise the integrity and confidentiality of user data on mobile devices.
Remediation
Immediate Action: Update Google Chrome on Android to version 146.0.7680.71 or later as provided by Google via the Play Store.
Proactive Monitoring: Review mobile device management logs for crashes or unexpected application behavior that may indicate heap corruption attempts.
Compensating Controls: Ensure that Google Play Protect is enabled on all enterprise-managed Android devices to detect and block potentially malicious web content.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high CVSS score underscores the necessity of prompt action to secure mobile environments. Administrators should prioritize the deployment of the latest Chrome updates to all Android endpoints to eliminate the underlying heap corruption risk.