ZeroHour

CVE-2026-87520

mass

Use-after-free in Dawn (WebGPU) in Chrome for Android enables sandbox-escaped code execution

CVSS 3.1
9.6 critical
EPSS
<1%p33
Published
()
Modified
AI analysis

CVE-2026-87520 is a use-after-free vulnerability (CWE-416) in Dawn, the WebGPU implementation in Google Chrome, affecting Chrome on Android prior to version 153.0.8010.36. An attacker triggers the flaw by persuading a user to open a crafted HTML page, with the CVSS user-interaction requirement reflecting that the victim must visit attacker-controlled content. Successful exploitation allows arbitrary code execution outside Chrome's sandbox (a scope change per the CVSS scoring), meaning the attacker escapes the renderer sandbox, with high impact on confidentiality, integrity, and availability. Only Chrome users on Android are affected per the published description. Exploitation has not been confirmed: the flaw is not in CISA's KEV catalog, there is no known public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (22nd percentile).

What to do: Update Chrome for Android to version 153.0.8010.36 or later, which is delivered via the Google Play Store; verify the installed build on chrome://version since auto-update may lag on idle or enterprise-managed devices. Until patched, treat unsolicited or untrusted links as risky on Android fleets, and have enterprise mobility admins check MDM/EMM reports for devices still on older Chrome builds.

Affected
Google Chrome for Androidprior to 153.0.8010.36
Estimated exposure
masswell over 1 billion Android users/installations (Chrome for Android has billions of Google Play installs) — Chrome is the dominant browser on Android and its Play Store listing shows billions of installs, so the theoretical affected installed base is in the billions, though exploitation additionally requires a user to visit a crafted page.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.