CVE-2026-6319
7.5Google · Chrome
A use after free vulnerability in the Payments component of Google Chrome on Android allows a remote attacker to execute arbitrary code via crafted HTML and user interaction.
Executive summary
A critical use after free vulnerability in Google Chrome on Android, identified as CVE-2026-6319, permits remote code execution through manipulated UI gestures.
Vulnerability
This is a use after free flaw (CWE-416) within the Payments component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to perform specific UI gestures while visiting a malicious HTML page.
Business impact
The ability for an attacker to achieve arbitrary code execution poses a severe risk to organizational security, potentially leading to full system compromise or sensitive data theft. Given the CVSS score of 7.5, this vulnerability represents a high risk to browser integrity. Organizations must account for the potential of unauthorized access to user accounts or device-level information if the browser is leveraged as an entry point.
Remediation
Immediate Action: Update all instances of Google Chrome on Android to version 147.0.7727.101 or later immediately.
Proactive Monitoring: Monitor device logs and browser security alerts for unusual behavior or unauthorized navigation to untrusted domains.
Compensating Controls: Utilize mobile device management (MDM) policies to enforce browser updates and restrict the installation of software from untrusted third-party sources.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
CVE-2026-6319 presents a high risk due to its potential for arbitrary code execution. Security teams should prioritize the deployment of the latest Chrome update across all mobile assets to eliminate the underlying memory management defect. Ensure that users are prompted to apply updates immediately to maintain a secure browsing environment.