CVE-2026-84333
massUse-after-free in Dawn in Chrome on Android allows code execution outside sandbox
CVE-2026-84333 is a use-after-free memory-safety flaw (CWE-416) in Dawn, the WebGPU implementation in Google Chrome, affecting Chrome for Android builds prior to 152.0.7977.75. An attacker triggers it by luring a user to open a crafted HTML page in the vulnerable browser, consistent with the CVSS user-interaction requirement. Successful exploitation yields arbitrary code execution outside the browser sandbox, letting the attacker escape Chrome's process-level containment on the Android device. Only Chrome on Android is listed as affected; the data does not indicate whether other platforms or other Chromium-based browsers are impacted. There is no evidence of in-the-wild exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at just 0.3% (20th percentile).
What to do: Update Chrome on Android to 152.0.7977.75 or later via the Play Store or Settings > About Chrome, and verify managed/enterprise Android fleets have received the update. Because exploitation requires user interaction, users who cannot update immediately should avoid opening untrusted links; defenders should monitor for a KEV listing or public PoC given the critical CVSS score.
| google chrome | Android, prior to 152.0.7977.75 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.