CVE-2026-84353

Google · Chrome

A use after free vulnerability in the Shared Tab Groups component of Google Chrome on Android allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A critical use after free vulnerability in Google Chrome on Android enables remote code execution outside the browser sandbox, posing a severe threat to mobile device integrity.

Vulnerability

This is a use after free flaw (CWE-416) within the Shared Tab Groups feature that allows an unauthenticated, remote attacker to execute arbitrary code. The attack requires user interaction through social engineering to lure a victim into visiting a crafted HTML page.

Business impact

The vulnerability carries a CVSS score of 9.6, reflecting its critical severity due to the potential for full system compromise. Successful exploitation allows an attacker to escape the browser sandbox, potentially leading to unauthorized data access, theft of sensitive information, or complete takeover of the affected Android device.

Remediation

Immediate Action: Update Google Chrome on all affected Android devices to version 152.0.7977.75 or later immediately.

Proactive Monitoring: Review mobile device management (MDM) reports to identify and isolate devices running outdated versions of Chrome.

Compensating Controls: Deploy mobile security solutions that filter malicious URLs and block access to untrusted or suspicious websites that may attempt to leverage browser-based exploits.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of this vulnerability and the potential for sandbox escape, organizations must prioritize the deployment of the Chrome update across their mobile fleet. Ensure that automatic updates are enabled or enforced via enterprise management policies to mitigate the risk of remote code execution.

More Google CVEs all →

Sources