Impact
This vulnerability originates from an out‑of‑bounds write in the GPU subsystem of Chrome on Android. The flaw can be triggered by loading a maliciously crafted HTML page, allowing a remote attacker to escape the browser sandbox and potentially execute code with higher privileges. The weakness is classified as CWE‑787 and is rated as critical by Chromium security.
Affected Systems
Google Chrome for Android versions older than 149.0.7827.53 are affected. The issue exists in the stable channel and was discovered before the June 2026 release.
Risk and Exploitability
The CVSS score is 9.6, indicating critical severity, and the flaw is potentially exploitable via the network by serving a malicious web page to a user. EPSS score of 0.00035 indicates a very low but nonzero probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog, yet the Attack Vector is remote through web content. Given the critical nature, the risk is high for exposed devices until patched.
OpenCVE Enrichment
Debian DSA