CVE-2026-93372

Google · Chrome

A buffer overflow vulnerability in the WebGL component of Google Chrome on Android allows a remote attacker to execute arbitrary code outside the browser sandbox via a crafted HTML page.

Executive summary

A critical buffer overflow vulnerability in Google Chrome for Android enables remote code execution, posing a significant risk of full system compromise.

Vulnerability

This flaw is a buffer overflow (CWE-121) within the WebGL implementation. An unauthenticated remote attacker can trigger this vulnerability by enticing a user to visit a malicious HTML page, leading to arbitrary code execution outside the sandbox environment.

Business impact

The ability for an attacker to execute code outside the Chrome sandbox represents a total loss of confidentiality, integrity, and availability for the affected device. With a CVSS score of 9.6, this vulnerability is classified as critical, as it could facilitate unauthorized data access, the installation of persistent malware, or complete device takeover within an enterprise environment.

Remediation

Immediate Action: Update the Google Chrome application on all Android devices to version 153.0.8010.52 or later immediately.

Proactive Monitoring: Security teams should monitor mobile device management (MDM) logs for outdated browser versions and review network traffic for connections to suspicious or unrecognized domains.

Compensating Controls: While browser-based exploits are difficult to block, utilizing enterprise-grade mobile threat defense solutions can help detect malicious activity or unauthorized code execution attempts on Android endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the potential for remote code execution, organizations must prioritize the deployment of the Chrome update across all managed Android assets. Delaying this update exposes the organization to significant risk, as the flaw allows attackers to bypass core security boundaries provided by the browser sandbox.

More Google CVEs all →

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.6 (3.1)
  4. Analyst report written

Sources