← Terug naar overzicht

CVE-2026-85050 is a high-severity out-of-bounds write vulnerability in the WebGL component of Google Chrome on Android. The flaw affects versions prior to 152.0.7977.82 and allows a remote attacker to execute arbitrary code outside the browser sandbox. Exploitation is achieved by luring a victim to a specially crafted HTML page. The vulnerability has been rated High by the Chromium security team. A fix was shipped in the stable channel update released in September 2026. No additional exploit details or active in-the-wild exploitation indicators are provided in the advisory. Users are advised to update Google Chrome on Android to version 152.0.7977.82 or later.

Affected products

  • Google Chrome on Android (prior to 152.0.7977.82)

Related CVE's

  • CVE-2026-85050

Categories

  • Mobile & IoT
  • Web Technologies
  • Zero-Day Vulnerabilities