ZeroHour

CVE-2026-79282

mass

Use-after-free in ANGLE in Google Chrome for Android allows sandbox-escaping RCE

CVSS 3.1
9.6 critical
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-79282 is a use-after-free (CWE-416) in ANGLE, Chrome's graphics abstraction layer used for rendering such as WebGL, in Google Chrome on Android. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, and the memory corruption is exploitable to execute arbitrary code outside the Chrome sandbox, a higher-impact outcome than typical renderer-sandboxed flaws. Any user running Chrome on Android prior to version 152.0.7977.65 is affected. There are currently no known public proof-of-concept exploits, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS puts the 30-day exploitation probability at a modest 0.4%. Given the Critical Chromium severity rating and the browser's reach, patching should still be treated as urgent.

What to do: Update Chrome on Android to 152.0.7977.65 or later (via Google Play → Chrome, then confirm the build at chrome://version). Until patched, exercise caution with links from untrusted sources, since exploitation requires visiting a crafted HTML page. Administrators should use MDM to verify managed Android fleets have received the updated build and monitor Google's Chrome release notes for related fixes.

Affected
google Chrome (on Android)All Android versions prior to 152.0.7977.65 (fixed in 152.0.7977.65)
Estimated exposure
massorder of billions of users (Chrome for Android builds before 152.0.7977.65) — Chrome is the default or dominant browser on most Android devices with roughly 3+ billion global users, and effectively all Android users on builds older than 152.0.7977.65 are affected until the update reaches them.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.