CVE-2026-79282
massUse-after-free in ANGLE in Google Chrome for Android allows sandbox-escaping RCE
CVE-2026-79282 is a use-after-free (CWE-416) in ANGLE, Chrome's graphics abstraction layer used for rendering such as WebGL, in Google Chrome on Android. A remote attacker can trigger the flaw by persuading a user to open a crafted HTML page, and the memory corruption is exploitable to execute arbitrary code outside the Chrome sandbox, a higher-impact outcome than typical renderer-sandboxed flaws. Any user running Chrome on Android prior to version 152.0.7977.65 is affected. There are currently no known public proof-of-concept exploits, no CISA KEV listing, and no confirmed in-the-wild exploitation; EPSS puts the 30-day exploitation probability at a modest 0.4%. Given the Critical Chromium severity rating and the browser's reach, patching should still be treated as urgent.
What to do: Update Chrome on Android to 152.0.7977.65 or later (via Google Play → Chrome, then confirm the build at chrome://version). Until patched, exercise caution with links from untrusted sources, since exploitation requires visiting a crafted HTML page. Administrators should use MDM to verify managed Android fleets have received the updated build and monitor Google's Chrome release notes for related fixes.
| google Chrome (on Android) | All Android versions prior to 152.0.7977.65 (fixed in 152.0.7977.65) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in ANGLE in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.