CVE-2026-102307: Uninitialized resource in Dawn
Uninitialized resource in Dawn in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154.0.8037.92
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-102331
- CVE-2026-102317
- CVE-2026-102312
- CVE-2026-102313
- CVE-2026-102299
- CVE-2026-102306
- CVE-2026-102323
- CVE-2026-102303
- CVE-2026-102311
- CVE-2026-102300
- CVE-2026-102326
- CVE-2026-102316
- CVE-2026-102304
- CVE-2026-102328
- CVE-2026-102309
- CVE-2026-102325
- CVE-2026-102308
- CVE-2026-102301
- CVE-2026-102319
- CVE-2026-102324
- CVE-2026-102318
- CVE-2026-102329
- CVE-2026-102315
- CVE-2026-102302
- CVE-2026-102321
- CVE-2026-102320
- CVE-2026-102310
- CVE-2026-102327
- CVE-2026-102330
- CVE-2026-102314
- CVE-2026-102305
Frequently Asked Questions
Which Chrome installations are affected?
Google Chrome on Android prior to version 154.0.8037.92 is affected. The provided information does not state whether desktop Chrome versions are affected.
What does an attacker need to exploit this issue?
An attacker needs to cause a user to load a crafted HTML page remotely. Successful exploitation can allow reading memory outside the sandbox.
How urgent is remediation?
Chromium rates the issue as High severity. Update Chrome on Android to version 154.0.8037.92 or later.