CVE-2026-84352
Google · Chrome
A use after free vulnerability in the WebGL component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome on Android allows unauthenticated remote attackers to achieve arbitrary code execution via malicious web content.
Vulnerability
This is a use after free vulnerability (CWE-416) within the WebGL implementation, which can be triggered by an unauthenticated remote attacker through a crafted HTML page to bypass sandbox protections and execute arbitrary code.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code outside the browser sandbox poses a severe threat to data integrity, confidentiality, and device security. With a CVSS score of 9.6, this vulnerability represents a critical risk that could lead to full system compromise, unauthorized access to sensitive user data, or lateral movement within the mobile environment.
Remediation
Immediate Action: Update Google Chrome for Android to version 152.0.7977.75 or later immediately.
Proactive Monitoring: Monitor device security logs for abnormal application crashes or unexpected outbound network connections initiated by the browser.
Compensating Controls: While browser updates are the primary defense, ensure that mobile device management policies are active and restrict the execution of untrusted web content where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical severity and the potential for remote code execution, organizations must prioritize the deployment of the Chrome update to all Android devices. Administrators should ensure that automatic updates are enabled and verify that the browser version has been successfully upgraded across the mobile fleet to eliminate the risk of exploitation.