CVE-2026-6319

7.5

Google · Chrome

A use after free vulnerability in the Payments component of Google Chrome on Android allows a remote attacker to execute arbitrary code via crafted HTML and user interaction.

Executive summary

A critical use after free vulnerability in Google Chrome on Android, identified as CVE-2026-6319, permits remote code execution through manipulated UI gestures.

Vulnerability

This is a use after free flaw (CWE-416) within the Payments component. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to perform specific UI gestures while visiting a malicious HTML page.

Business impact

The ability for an attacker to achieve arbitrary code execution poses a severe risk to organizational security, potentially leading to full system compromise or sensitive data theft. Given the CVSS score of 7.5, this vulnerability represents a high risk to browser integrity. Organizations must account for the potential of unauthorized access to user accounts or device-level information if the browser is leveraged as an entry point.

Remediation

Immediate Action: Update all instances of Google Chrome on Android to version 147.0.7727.101 or later immediately.

Proactive Monitoring: Monitor device logs and browser security alerts for unusual behavior or unauthorized navigation to untrusted domains.

Compensating Controls: Utilize mobile device management (MDM) policies to enforce browser updates and restrict the installation of software from untrusted third-party sources.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

CVE-2026-6319 presents a high risk due to its potential for arbitrary code execution. Security teams should prioritize the deployment of the latest Chrome update across all mobile assets to eliminate the underlying memory management defect. Ensure that users are prompted to apply updates immediately to maintain a secure browsing environment.

More Google CVEs

Sources