CVE-2026-87520
massUse-after-free in Dawn (WebGPU) in Chrome for Android enables sandbox-escaped code execution
CVE-2026-87520 is a use-after-free vulnerability (CWE-416) in Dawn, the WebGPU implementation in Google Chrome, affecting Chrome on Android prior to version 153.0.8010.36. An attacker triggers the flaw by persuading a user to open a crafted HTML page, with the CVSS user-interaction requirement reflecting that the victim must visit attacker-controlled content. Successful exploitation allows arbitrary code execution outside Chrome's sandbox (a scope change per the CVSS scoring), meaning the attacker escapes the renderer sandbox, with high impact on confidentiality, integrity, and availability. Only Chrome users on Android are affected per the published description. Exploitation has not been confirmed: the flaw is not in CISA's KEV catalog, there is no known public proof-of-concept, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days (22nd percentile).
What to do: Update Chrome for Android to version 153.0.8010.36 or later, which is delivered via the Google Play Store; verify the installed build on chrome://version since auto-update may lag on idle or enterprise-managed devices. Until patched, treat unsolicited or untrusted links as risky on Android fleets, and have enterprise mobility admins check MDM/EMM reports for devices still on older Chrome builds.
| Google Chrome for Android | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.