CVE-2026-87488
9.6Google · Chrome
A use after free vulnerability in the WebGL component of Google Chrome on Android allows remote attackers to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
A critical use after free vulnerability in Google Chrome on Android allows unauthenticated remote attackers to achieve arbitrary code execution, posing a severe risk to device integrity.
Vulnerability
This flaw is a use after free vulnerability (CWE-416) within the WebGL engine. An unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to code execution outside the browser sandbox.
Business impact
The CVSS score of 9.6 reflects the critical nature of this vulnerability, as it allows for full system compromise. Successful exploitation grants an attacker the ability to bypass sandbox protections, potentially leading to unauthorized data access, installation of persistent malware, or complete device takeover.
Remediation
Immediate Action: Update Google Chrome on all affected Android devices to version 153.0.8010.36 or later immediately.
Proactive Monitoring: Review mobile device management logs for unusual browser crashes or unexpected background process activity that may indicate exploitation attempts.
Compensating Controls: Ensure that Google Play Protect is enabled on all corporate-managed Android devices to detect and block malicious applications or web content.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical severity and the potential for sandbox escape, organizations must prioritize updating all instances of Google Chrome on Android devices. Failure to patch this vulnerability leaves endpoints exposed to remote code execution attacks that require only minimal user interaction.
More Google CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.6 (3.1)
- Analyst report written
- Published in the daily brief critical section, early-warning entry