


Perceptive Security
SOC/SIEM Consultancy

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a craf…
Published:
2 september 2026 om 00:00:00
Alert date:
2 september 2026 om 13:02:55
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities
A critical use-after-free vulnerability exists in WebGL in Google Chrome for Android prior to version 152.0.7977.75. The flaw allows a remote attacker to execute arbitrary code outside the sandbox by luring a victim to a crafted HTML page. The vulnerability is rated Critical by the Chromium security team. Successful exploitation could lead to full compromise of the affected device beyond the browser sandbox. The issue has been addressed in Chrome stable channel update 152.0.7977.75. Users on Android are strongly advised to update immediately. The vulnerability is tracked as CVE-2026-84352 and details are published on NVD.
Technical details
Mitigation steps:
Affected products:
Google Chrome for Android (prior to 152.0.7977.75)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84352
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
https://issues.chromium.org/issues/546260492
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
