CVE-2026-102331: Buffer overflow in ANGLE
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.92 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 154.0.8037.92
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-102317
- CVE-2026-102312
- CVE-2026-102313
- CVE-2026-102299
- CVE-2026-102306
- CVE-2026-102307
- CVE-2026-102323
- CVE-2026-102303
- CVE-2026-102311
- CVE-2026-102300
- CVE-2026-102326
- CVE-2026-102316
- CVE-2026-102304
- CVE-2026-102328
- CVE-2026-102309
- CVE-2026-102325
- CVE-2026-102308
- CVE-2026-102301
- CVE-2026-102319
- CVE-2026-102324
- CVE-2026-102318
- CVE-2026-102329
- CVE-2026-102315
- CVE-2026-102302
- CVE-2026-102321
- CVE-2026-102320
- CVE-2026-102310
- CVE-2026-102327
- CVE-2026-102330
- CVE-2026-102314
- CVE-2026-102305
Frequently Asked Questions
Which deployments are affected?
Google Chrome on Android versions earlier than 154.0.8037.92 are affected. The provided information does not establish whether other Chrome platforms are impacted.
What does exploitation require?
A remote attacker would need to cause a user to load a crafted HTML page. Successful exploitation could potentially result in arbitrary code execution outside the Chrome sandbox.
How should teams identify potentially vulnerable devices?
Inventory Android devices running Google Chrome and compare their installed Chrome version with 154.0.8037.92. Devices below that version should be treated as potentially affected.