CVE-2026-76039: Incorrect reference resolution in Core
Chromium CVE-2026-76039: Incorrect reference resolution in Core
Other sources
Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.4129.101 - Upgrade
Upgrade
Microsoft Edge (Chromium-based) / Google Chrome on Androidto a version that resolves this vulnerability.Fixed in 151.0.7922.169 - Compensating control
Mitigate by avoiding social-engineering vectors (e.g., do not open untrusted/crafted HTML pages) since the vulnerability is exploitable via a crafted HTML page used for social engineering.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which deployments are exposed?
Google Chrome for Android is affected when it is running a version earlier than 151.0.7922.169. The issue is in Chrome Core and is triggered through a crafted HTML page.
What does an attacker need to exploit this issue?
An attacker must get a user to interact with a crafted HTML page; the advisory explicitly identifies social engineering as part of the attack scenario. The stated impact is disclosure of sensitive information to a remote attacker.