Use-after-free in WebGL in Chrome for Android allows out-of-sandbox code execution
AI analysis
CVE-2026-84352 is a use-after-free memory-safety flaw (CWE-416) in the WebGL component of Google Chrome on Android, rated Critical with a CVSS 3.1 score of 9.6. It is triggered when a remote attacker persuades a user to open a specially crafted HTML page in the vulnerable browser. Successful exploitation lets the attacker execute arbitrary code outside the browser's sandbox, meaning the compromise is not limited to the renderer process and could yield high-impact confidentiality, integrity, and availability loss on the device. Only Chrome on Android prior to version 152.0.7977.75 is affected per the advisory, while desktop Chrome is not listed as impacted. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation within 30 days, though it has drawn public coverage warning users about critical Chrome flaws on malicious websites.
What to do: Update Chrome for Android via the Play Store to version 152.0.7977.75 or later as soon as it is available, and force-update managed Android fleets via MDM/enterprise Chrome management. Until patched, avoid opening links from untrusted sources in Chrome on Android. Users of other Chromium-based Android browsers should watch for corresponding updates, since the underlying Chromium code is shared.
Affected
| google chrome (on Android) | prior to 152.0.7977.75 |
Estimated exposure
mass≈5+ billion installations (Chrome for Android has 5B+ Play Store installs and is the default browser on most Android devices) — Chrome for Android carries over five billion Play Store installs and is preinstalled or widely adopted across the Android ecosystem, so the Android-specific affected base is on the order of billions of devices.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.