CVE-2026-84333

9.6

Google · Chrome

A use after free vulnerability in the Dawn component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome on Android enables remote attackers to achieve arbitrary code execution outside the sandbox, posing a severe risk to device integrity.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Dawn component. It can be triggered by an unauthenticated remote attacker who lures a user to visit a malicious HTML page.

Business impact

The ability for a remote attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected device. Given the CVSS score of 9.6, this vulnerability could lead to unauthorized data access, installation of persistent malware, and complete loss of device control, resulting in significant reputational and operational damage.

Remediation

Immediate Action: Update Google Chrome on all affected Android devices to version 152.0.7977.75 or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Monitor network traffic for connections to unknown or suspicious domains and review mobile device management (MDM) logs for unusual application behavior.

Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to provide an additional layer of security against potentially malicious application activity.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability carries a critical severity rating due to the potential for remote code execution and the bypass of browser security boundaries. Security teams should prioritize the deployment of the Chrome update across their mobile fleet to eliminate the risk of exploitation. Failure to patch may expose users to advanced browser-based attacks that compromise the entire operating system.

More Google CVEs all →

Sources