Description
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-21
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug in the GPU driver code of Google Chrome on Android allows a malicious HTML document to exploit a freed memory area after a renderer process crash. The defect can lead to a sandbox escape, granting an attacker arbitrary code execution on the device. The weakness is a classic memory‑corruption error, identified as CWE‑416.

Affected Systems

Google Chrome for Android versions earlier than 150.0.7871.182 are vulnerable. Any device running a compromised renderer process that loads a specially crafted web page may be affected.

Risk and Exploitability

The CVSS score of 9.6 marks the issue as critical, yet the EPSS score of <1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Attackers would need to entice an Android device to load malicious content that triggers the renderer crash and then use the freed memory to escape the sandbox. No public exploits are known, but the high severity warrants immediate attention.

Generated by OpenCVE AI on August 4, 2026 at 00:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome on Android to version 150.0.7871.182 or later, as released by Google.
  • Disable GPU hardware acceleration in Chrome via chrome://flags if an immediate update is not possible, which mitigates the use‑after‑free path by removing the vulnerable code path.
  • Restrict or monitor the installation of applications that can open URLs in Chrome to reduce the chance of malicious HTML content being delivered to the renderer process.

Generated by OpenCVE AI on August 4, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via GPU Use‑After‑Free in Chrome on Android

Thu, 30 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via GPU Use‑After‑Free in Chrome on Android

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in GPU Rendering Leading to Sandbox Escapes in Chrome on Android

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in GPU Rendering Leading to Sandbox Escapes in Chrome on Android

Wed, 22 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 21 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Description Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-22T13:38:52.783Z

Reserved: 2026-07-20T22:23:07.394Z

Link: CVE-2026-16424

cve-icon Vulnrichment

Updated: 2026-07-22T13:38:05.591Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses