CVE-2026-84352: Use After Free
Published Sep 1, 2026
·Updated
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
Affected Software
1 affected component
Google Google Chrome (Android)<152.0.7977.75
Event History
Sep 1, 2026
CVE Published
via MITRE·11:42 PM
Data Sourced
via MITRE·11:42 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Chrome installations are affected?
Google Chrome on Android before version 152.0.7977.75 is affected. The provided data does not identify affected desktop versions despite one reference being a desktop stable-channel update.
2
What does an attacker need to exploit this issue?
The issue can be triggered remotely through a crafted HTML page. The description does not state that the attacker needs prior access, authentication, or local code execution.
3
What is the potential impact of successful exploitation?
A successful exploit could allow arbitrary code execution outside the Chrome sandbox. Chromium classifies the issue as Critical.