CVE-2026-6358

8.8

Google · Chrome

A use-after-free vulnerability exists in the XR component of Google Chrome on Android, potentially allowing remote attackers to execute arbitrary code.

Executive summary

A high-severity use-after-free vulnerability in Google Chrome’s XR component on Android poses a significant risk of arbitrary code execution.

Vulnerability

This is a use-after-free memory corruption vulnerability within the XR (Extended Reality) subsystem. The attack vector is network-based and requires user interaction, but does not require prior authentication.

Business impact

Successful exploitation of this flaw can result in full system compromise, allowing an attacker to execute arbitrary code with the privileges of the browser. Given the CVSS score of 8.8, this represents a high risk to organizational data confidentiality, integrity, and availability, particularly for mobile devices used in enterprise environments.

Remediation

Immediate Action: Update Google Chrome on all affected Android devices to the latest patched version available via the Google Play Store.

Proactive Monitoring: Monitor device logs for unusual browser crashes or unexpected behavior that may indicate memory corruption attempts.

Compensating Controls: Ensure that enterprise mobile device management (MDM) policies restrict the installation of untrusted applications and enforce mandatory browser updates.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this vulnerability necessitates immediate attention. Organizations should prioritize patching all instances of Google Chrome on Android to prevent potential exploitation. Failure to update may expose end-user devices to remote code execution and subsequent compromise of corporate credentials or sensitive data.

More Google CVEs