CVE-2026-13028: Use after free in WebGL
Chromium: CVE-2026-13028 Use after free in WebGL
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.7827.196 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.4022.96 - Upgrade
Upgrade
Chromium (Google Chrome on Android)to a version that resolves this vulnerability.Fixed in 149.0.7827.197 - Compensating control
To reduce exposure to the WebGL use-after-free (CVE-2026-13028) on Android browsers, avoid loading untrusted/crafted HTML pages in Google Chrome on Android until updated to 149.0.7827.197 or later.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-13028?
CVE-2026-13028 has a critical severity level rated at 9.6 based on the CVSS scoring.
How do I fix CVE-2026-13028?
To fix CVE-2026-13028, users should update Google Chrome on Android to version 149.0.7827.197 or later.
What type of vulnerability is CVE-2026-13028?
CVE-2026-13028 is classified as a 'Use After Free' vulnerability in WebGL.
What are the potential impacts of CVE-2026-13028?
Exploitation of CVE-2026-13028 could allow a remote attacker to perform a sandbox escape via a crafted HTML page.
Which software is affected by CVE-2026-13028?
CVE-2026-13028 affects the Google Chrome browser on Android prior to version 149.0.7827.197.