Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2026-85050: Chrome for Android can run malicious code via WebGL
CVE-2026-85050 · published today
Summary
If you use Chrome on Android versions before 152.0.7977.82, a specially crafted web page could cause the browser to write data outside its safe area and let an attacker run code on the device. This could let the attacker take control of the phone or access data. Update Chrome to the latest version to protect against this risk.
What to do
- Update google chrome to version 152.0.7977.82 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| chrome | < 152.0.7977.82 |
Original advisory text
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium securit...
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Severity
9.6
Critical
Type
CWE-787Out-of-bounds Write
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen3 Sep 2026
Monitor software like this
Free during beta