CVE-2026-85050: Out of bounds write in WebGL
Out of bounds write in WebGL in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 152.0.7977.82
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
Which users are exposed to this issue?
The issue affects Google Chrome on Android before version 152.0.7977.82. The vulnerability information also lists Google Chrome generally, but does not provide a separate affected version range for other platforms.
What does exploitation require?
An attacker needs to induce a user to load a crafted HTML page in a vulnerable Chrome browser. Successful exploitation can allow arbitrary code execution outside the browser sandbox.
Is there a documented temporary mitigation if updates cannot be deployed immediately?
No temporary mitigation or configuration workaround is provided in the available information. Updating affected Android Chrome installations to 152.0.7977.82 or later is the documented version boundary for exposure.