CVE-2026-85050

9.6

Google · Chrome

A remote attacker can execute arbitrary code outside the browser sandbox by tricking a user into visiting a crafted HTML page that triggers an out of bounds write in WebGL.

Executive summary

An out of bounds write vulnerability in Google Chrome for Android allows remote attackers to achieve arbitrary code execution via a specially crafted HTML page.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) within the WebGL component. An unauthenticated remote attacker can trigger this flaw through a crafted HTML page, requiring user interaction to execute the malicious code.

Business impact

The ability for an attacker to execute code outside the browser sandbox poses a severe threat to user privacy and device integrity. With a CVSS score of 9.6, this vulnerability facilitates full system compromise, potentially leading to unauthorized data access, the installation of malicious software, and complete loss of confidentiality and integrity on the affected mobile device.

Remediation

Immediate Action: Update Google Chrome on all Android devices to version 152.0.7977.82 or later immediately.

Proactive Monitoring: Monitor device traffic for connections to suspicious or unknown domains that may be hosting malicious HTML content.

Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to assist in detecting and blocking malicious applications or web-based threats.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and its potential for sandbox escape, organizations must prioritize patching all mobile assets running Google Chrome. Administrators should enforce update policies to ensure devices remain on the latest stable version provided by the vendor.

More Google CVEs

Sources