CVE-2026-4439
8.8Google · Chrome
A critical out-of-bounds memory access vulnerability in Google Chrome for Android's WebGL component allows remote attackers to potentially achieve a sandbox escape via a crafted HTML page.
Executive summary
A critical sandbox escape vulnerability exists in Google Chrome for Android that could allow a remote attacker to compromise the host device through malicious web content.
Vulnerability
This is an out-of-bounds memory access flaw located in the WebGL component of the browser. The vulnerability allows an unauthenticated, remote attacker to trigger memory corruption and potentially escape the browser sandbox by enticing a user to visit a specially crafted HTML page.
Business impact
The ability to escape the browser sandbox represents a critical security failure, as it allows an attacker to bypass the primary boundary between malicious web content and the underlying operating system. Given the CVSS score of 8.8, this vulnerability poses a high risk of unauthorized system access, data theft, or device control. Successful exploitation could lead to significant reputational damage and the compromise of sensitive user data stored on the affected Android devices.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 146.0.7680.153 or later immediately.
Proactive Monitoring: Monitor device logs for unusual browser crashes or unexpected background process activity that may indicate attempts to exploit memory corruption flaws.
Compensating Controls: While there is no direct virtual patch for this browser-level flaw, ensure that Google Play Protect is enabled on all Android endpoints to detect and block malicious applications or web-based threats.
Exploitation status
Public Exploit Available: No confirmed public exploit (exploit_available: false).
Analyst recommendation
Due to the severity of a sandbox escape vulnerability and the relative ease with which users can be targeted through malicious websites, organizations must prioritize patching. System administrators should push the latest Chrome update to all managed mobile devices as soon as possible to mitigate the risk of remote compromise.