Use After Free Vulnerability in WebGL for Google Chrome on Android
CVE-2026-9876

9.6CRITICAL

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
28 May 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 2,260

What is CVE-2026-9876?

CVE-2026-9876 is a critical vulnerability identified in the WebGL component of Google Chrome specifically affecting the Android platform in versions prior to 148.0.7778.216. WebGL is a web standard that enables 3D rendering in browsers without requiring additional plugins. The vulnerability stems from a "use after free" flaw, which occurs when memory that is no longer allocated is accessed. This can allow attackers to escape the browser's sandbox environment, resulting in severe security risks. If exploited, this vulnerability could enable malicious actors to execute arbitrary code on the user’s device, potentially leading to unauthorized access to sensitive information or control over the device itself. Organizations relying on Chrome for secure web applications may face increased risks as a result of this vulnerability.

Potential impact of CVE-2026-9876

  1. Remote Code Execution: This vulnerability allows attackers to potentially execute arbitrary code remotely on affected devices, leading to unauthorized access and manipulation of user data. This could have severe consequences, particularly in enterprise environments handling sensitive information.

  2. Sandbox Escalation: Exploiting this vulnerability can enable attackers to escape the browser's sandbox, undermining the security barrier that protects the operating system and other applications. Such an escalation could allow for the installation of malware or other forms of compromise.

  3. Increased Threat Exposure: Given the widespread use of Google Chrome on Android devices, this vulnerability increases overall exposure to threat actors. Compromised devices could serve as entry points for larger-scale attacks, impacting not only individual users but also corporate networks and data infrastructures.

Affected Version(s)

Chrome 148.0.7778.216

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.