ZeroHour

CVE-2026-84333

mass

Use-after-free in Dawn in Chrome on Android allows code execution outside sandbox

CVSS 3.1
9.6 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

CVE-2026-84333 is a use-after-free memory-safety flaw (CWE-416) in Dawn, the WebGPU implementation in Google Chrome, affecting Chrome for Android builds prior to 152.0.7977.75. An attacker triggers it by luring a user to open a crafted HTML page in the vulnerable browser, consistent with the CVSS user-interaction requirement. Successful exploitation yields arbitrary code execution outside the browser sandbox, letting the attacker escape Chrome's process-level containment on the Android device. Only Chrome on Android is listed as affected; the data does not indicate whether other platforms or other Chromium-based browsers are impacted. There is no evidence of in-the-wild exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS puts the 30-day exploitation probability at just 0.3% (20th percentile).

What to do: Update Chrome on Android to 152.0.7977.75 or later via the Play Store or Settings > About Chrome, and verify managed/enterprise Android fleets have received the update. Because exploitation requires user interaction, users who cannot update immediately should avoid opening untrusted links; defenders should monitor for a KEV listing or public PoC given the critical CVSS score.

Affected
google chromeAndroid, prior to 152.0.7977.75
Estimated exposure
mass≈3 billion+ Chrome for Android users — Chrome is the dominant browser on Android, the world's most widely used mobile operating system, implying an install base in the billions, though only users who open attacker-crafted pages are directly at risk per incident.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.