CVE-2026-85044: Use of released resource in Mobile
Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82 - Upgrade
Upgrade
Google Chrome (Android)to a version that resolves this vulnerability.Fixed in 152.0.7977.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which users are exposed?
Users of Google Chrome on Android with versions earlier than 152.0.7977.82 are affected. The issue is described specifically in the Android mobile context.
What does exploitation require?
A remote attacker needs to use social engineering to persuade a user to interact with a crafted HTML page.
What is the security impact?
Successful exploitation can bypass the web origin policy.