CVE-2026-79142
8.8Google · Chrome
A buffer overflow vulnerability in the ANGLE component of Google Chrome for Android allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A high-severity buffer overflow vulnerability in Google Chrome for Android allows unauthenticated remote attackers to execute arbitrary code on affected devices.
Vulnerability
This is a buffer overflow flaw within the ANGLE graphics engine component. The vulnerability is exploitable by an unauthenticated remote attacker who can trigger arbitrary code execution outside the browser sandbox by enticing a user to navigate to a crafted HTML page.
Business impact
The ability to execute arbitrary code outside the browser sandbox represents a significant risk to data confidentiality, integrity, and availability. A successful compromise could lead to full device takeover, unauthorized access to sensitive user data, or the installation of malicious software. With a CVSS score of 8.8, this vulnerability poses a high risk to organizational security posture.
Remediation
Immediate Action: Update Google Chrome on all Android devices to version 152.0.7977.65 or later to apply the necessary security patches.
Proactive Monitoring: Monitor device logs and endpoint security telemetry for unusual browser behavior or unexpected outbound network connections from the mobile browser process.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android endpoints to provide an additional layer of defense against malicious applications and web content.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the capability for remote code execution and sandbox escape, this vulnerability must be treated with high urgency. Organizations managing mobile device fleets should prioritize the deployment of the latest Chrome browser updates to all Android assets to mitigate the risk of exploitation.