CVE-2026-87438
9.6Google · Chrome
An out of bounds write vulnerability in the WebGL component of Google Chrome on Android allows a remote attacker to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
Executive summary
A critical out of bounds write vulnerability in Google Chrome for Android enables remote code execution, posing a severe risk to device integrity and user data.
Vulnerability
This is an out of bounds write flaw (CWE-787) located within the WebGL component. The vulnerability can be triggered by an unauthenticated remote attacker who lures a user into visiting a specially crafted HTML page.
Business impact
The ability for a remote attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected device. Given the CVSS score of 9.6, this vulnerability is critical: it could lead to complete data exfiltration, installation of persistent malware, or unauthorized access to sensitive local resources. Organizations relying on Android devices for business operations must treat this as a high-priority threat to mobile security.
Remediation
Immediate Action: Update all instances of Google Chrome on Android to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Monitor mobile device management (MDM) logs for outdated browser versions and review network traffic for connections to suspicious or unknown domains that may be hosting malicious HTML content.
Compensating Controls: Ensure that Google Play Protect is enabled on all enterprise Android devices to assist in detecting potentially harmful applications or malicious web content.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the critical nature of this vulnerability and its potential for full sandbox escape, immediate patching is required. IT administrators should prioritize the deployment of the update via mobile device management solutions to ensure all managed devices are protected against potential remote code execution attacks.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry