CVE-2026-85050
9.6Google · Chrome
A remote attacker can execute arbitrary code outside the browser sandbox by tricking a user into visiting a crafted HTML page that triggers an out of bounds write in WebGL.
Executive summary
An out of bounds write vulnerability in Google Chrome for Android allows remote attackers to achieve arbitrary code execution via a specially crafted HTML page.
Vulnerability
This is an out of bounds write vulnerability (CWE-787) within the WebGL component. An unauthenticated remote attacker can trigger this flaw through a crafted HTML page, requiring user interaction to execute the malicious code.
Business impact
The ability for an attacker to execute code outside the browser sandbox poses a severe threat to user privacy and device integrity. With a CVSS score of 9.6, this vulnerability facilitates full system compromise, potentially leading to unauthorized data access, the installation of malicious software, and complete loss of confidentiality and integrity on the affected mobile device.
Remediation
Immediate Action: Update Google Chrome on all Android devices to version 152.0.7977.82 or later immediately.
Proactive Monitoring: Monitor device traffic for connections to suspicious or unknown domains that may be hosting malicious HTML content.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to assist in detecting and blocking malicious applications or web-based threats.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and its potential for sandbox escape, organizations must prioritize patching all mobile assets running Google Chrome. Administrators should enforce update policies to ensure devices remain on the latest stable version provided by the vendor.