CVE-2026-84353
Google · Chrome
A use after free vulnerability in the Shared Tab Groups component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome on Android enables remote code execution outside the browser sandbox, posing a severe threat to mobile device integrity.
Vulnerability
This is a use after free flaw (CWE-416) within the Shared Tab Groups feature that allows an unauthenticated, remote attacker to execute arbitrary code. The attack requires user interaction through social engineering to lure a victim into visiting a crafted HTML page.
Business impact
The vulnerability carries a CVSS score of 9.6, reflecting its critical severity due to the potential for full system compromise. Successful exploitation allows an attacker to escape the browser sandbox, potentially leading to unauthorized data access, theft of sensitive information, or complete takeover of the affected Android device.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 152.0.7977.75 or later immediately.
Proactive Monitoring: Review mobile device management (MDM) reports to identify and isolate devices running outdated versions of Chrome.
Compensating Controls: Deploy mobile security solutions that filter malicious URLs and block access to untrusted or suspicious websites that may attempt to leverage browser-based exploits.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical nature of this vulnerability and the potential for sandbox escape, organizations must prioritize the deployment of the Chrome update across their mobile fleet. Ensure that automatic updates are enabled or enforced via enterprise management policies to mitigate the risk of remote code execution.