CVE-2026-84333: Use after free in Dawn
Chromium: CVE-2026-84333 Use after free in Dawn
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.75 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.65 - Upgrade
Upgrade
Chromium / Google Chrome (Android)to a version that resolves this vulnerability.Fixed in 152.0.7977.75 - Compensating control
On Android, mitigate active exploitation by limiting exposure to untrusted web content (e.g., avoid opening crafted HTML from untrusted sources) until Chrome is upgraded to 152.0.7977.75 or later.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84353
- CVE-2026-84352
- CVE-2026-84354
- CVE-2026-84359
- CVE-2026-84357
- CVE-2026-84324
- CVE-2026-84349
- CVE-2026-84326
- CVE-2026-84351
- CVE-2026-84325
- CVE-2026-84328
- CVE-2026-84347
- CVE-2026-84323
- CVE-2026-84355
- CVE-2026-84358
- CVE-2026-84332
- CVE-2026-84330
- CVE-2026-84334
- CVE-2026-84348
- CVE-2026-84335
- CVE-2026-84327
- CVE-2026-84329
- CVE-2026-84356
- CVE-2026-84350
- CVE-2026-84331
Frequently Asked Questions
Which deployments are affected?
The issue affects Google Chrome on Android before version 152.0.7977.75. The provided data does not identify affected desktop Chrome versions or other Dawn consumers.
What must an attacker do to exploit this issue?
A remote attacker would need to cause the target to process a crafted HTML page. Successful exploitation can result in arbitrary code execution outside the Chrome sandbox.
How can I determine whether a device needs remediation?
Check the installed Google Chrome version on Android. Versions earlier than 152.0.7977.75 are affected according to the provided data.