CVE-2026-76036: Buffer overflow in Dawn
Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which systems are exposed to this vulnerability?
Google Chrome on Android is affected when it is earlier than version 151.0.7922.169. The issue is remotely reachable through a crafted HTML page and is rated Critical by Chromium.
What does an attacker need to exploit it?
An attacker needs to induce the user to load a crafted HTML page in a vulnerable Chrome for Android installation. The reported impact is arbitrary code execution outside the browser sandbox.
What should be done to remediate the issue?
Update Chrome on Android to version 151.0.7922.169 or later. The provided information does not identify an alternative mitigation for installations that cannot yet be updated.