CVE-2026-84352: Use after free in WebGL
Chromium: CVE-2026-84352 Use after free in WebGL
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.75 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.4191.65 - Upgrade
Upgrade
Google Chrome/Chromium (Android)to a version that resolves this vulnerability.Fixed in 152.0.7977.75 - Upgrade
Upgrade
Microsoft Edge (Chromium-based)to a version that resolves this vulnerability.Fixed in 152.0.7977.75
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-84353
- CVE-2026-84354
- CVE-2026-84359
- CVE-2026-84357
- CVE-2026-84324
- CVE-2026-84349
- CVE-2026-84326
- CVE-2026-84333
- CVE-2026-84351
- CVE-2026-84325
- CVE-2026-84328
- CVE-2026-84347
- CVE-2026-84323
- CVE-2026-84355
- CVE-2026-84358
- CVE-2026-84332
- CVE-2026-84330
- CVE-2026-84334
- CVE-2026-84348
- CVE-2026-84335
- CVE-2026-84327
- CVE-2026-84329
- CVE-2026-84356
- CVE-2026-84350
- CVE-2026-84331
Frequently Asked Questions
Which Chrome installations are affected?
Google Chrome on Android before version 152.0.7977.75 is affected. The provided data does not identify affected desktop versions despite one reference being a desktop stable-channel update.
What does an attacker need to exploit this issue?
The issue can be triggered remotely through a crafted HTML page. The description does not state that the attacker needs prior access, authentication, or local code execution.
What is the potential impact of successful exploitation?
A successful exploit could allow arbitrary code execution outside the Chrome sandbox. Chromium classifies the issue as Critical.