SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-84352

CRITICAL · CVSS 9.6 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in WebGL within Google Chrome on Android prior to version 152.0.7977.75 allows remote attackers to execute arbitrary code outside the browser's sandbox through specially crafted HTML content. This poses a critical risk to users of affected Android devices, particularly those who frequently access untrusted web pages. Organizations and individuals using these versions of Chrome should prioritize updates to mitigate potential exploitation.

CVE
CVE-2026-84352
Severity
CRITICAL
CVSS
9.6
EPSS
0.31%
Android Chrome

Original NVD Description

Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Related CVEs

Other vulnerabilities affecting the same vendor(s)