CVE-2026-4439: Out of bounds memory access in WebGL
Published Jan 15, 2026
·Updated
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Credit
Goodluck
Affected Software
6 affected componentsFixes available
Google Google Chrome for Android<146.0.7680.153
Google Chrome<146.0.7680.153
146.0.7680.153
All of the following
Google Chrome<146.0.7680.153
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Jan 15, 2026
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Mar 20, 2026
CVE Published
via MITRE·01:34 AM
Data Sourced
via MITRE·01:34 AM
DescriptionWeakness
Data Sourced
via NVD·02:16 AM
DescriptionSeverityWeaknessAffected Software
Sep 22, 58202
Event
via FIRST·12:10 PM
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-4440
- CVE-2026-4441
- CVE-2026-4442
- CVE-2026-4443
- CVE-2026-4444
- CVE-2026-4445
- CVE-2026-4446
- CVE-2026-4447
- CVE-2026-4448
- CVE-2026-4449
- CVE-2026-4450
- CVE-2026-4451
- CVE-2026-4452
- CVE-2026-4453
- CVE-2026-4454
- CVE-2026-4455
- CVE-2026-4456
- CVE-2026-4457
- CVE-2026-4458
- CVE-2026-4459
- CVE-2026-4460
- CVE-2026-4461
- CVE-2026-4462
- CVE-2026-4463
- CVE-2026-4464
Frequently Asked Questions
1
What is the severity of CVE-2026-4439?
The severity of CVE-2026-4439 is classified as Critical.
2
How do I fix CVE-2026-4439?
To fix CVE-2026-4439, you should update Google Chrome for Android to version 146.0.7680.153 or later.
3
What causes the vulnerability CVE-2026-4439?
CVE-2026-4439 is caused by an out of bounds memory access in WebGL in Google Chrome on Android.
4
Who is affected by CVE-2026-4439?
CVE-2026-4439 affects users of Google Chrome for Android prior to version 146.0.7680.153.
5
Can CVE-2026-4439 allow remote attacks?
Yes, CVE-2026-4439 allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page.