CVE-2026-87438

9.6

Google · Chrome

An out of bounds write vulnerability in the WebGL component of Google Chrome on Android allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted HTML page.

Executive summary

A critical out of bounds write vulnerability in Google Chrome for Android enables remote code execution, posing a severe risk to device integrity and user data.

Vulnerability

This is an out of bounds write flaw (CWE-787) located within the WebGL component. The vulnerability can be triggered by an unauthenticated remote attacker who lures a user into visiting a specially crafted HTML page.

Business impact

The ability for a remote attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected device. Given the CVSS score of 9.6, this vulnerability is critical: it could lead to complete data exfiltration, installation of persistent malware, or unauthorized access to sensitive local resources. Organizations relying on Android devices for business operations must treat this as a high-priority threat to mobile security.

Remediation

Immediate Action: Update all instances of Google Chrome on Android to version 153.0.8010.36 or later immediately.

Proactive Monitoring: Monitor mobile device management (MDM) logs for outdated browser versions and review network traffic for connections to suspicious or unknown domains that may be hosting malicious HTML content.

Compensating Controls: Ensure that Google Play Protect is enabled on all enterprise Android devices to assist in detecting potentially harmful applications or malicious web content.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the critical nature of this vulnerability and its potential for full sandbox escape, immediate patching is required. IT administrators should prioritize the deployment of the update via mobile device management solutions to ensure all managed devices are protected against potential remote code execution attacks.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written
  5. Published in the daily brief critical section, early-warning entry

Sources