Skip to main content
Vulnerability Database/CVE-2026-102307

CVE-2026-102307: Google Chrome Information Disclosure Flaw

CVE-2026-102307 is an information disclosure vulnerability in Google Chrome on Android that allows attackers to read memory outside the sandbox through malicious web pages. This article covers technical details, affected versions, security impact, and mitigation steps.

Published:

CVE-2026-102307 Overview

CVE-2026-102307 is an uninitialized resource vulnerability [CWE-908] in the Dawn component of Google Chrome on Android. Dawn is Chrome's implementation of the WebGPU standard. The flaw affects Chrome versions prior to 154.0.8037.92. A remote attacker can trick a user into visiting a crafted HTML page and read memory outside the browser sandbox. Chromium's internal severity rating for this issue is High, while the NVD assigned a CVSS score of 4.7 reflecting the requirement for user interaction and limited confidentiality impact.

Critical Impact

Successful exploitation allows a remote attacker to disclose memory contents from outside the WebGPU sandbox on Android devices running vulnerable Chrome builds.

Affected Products

  • Google Chrome on Android prior to 154.0.8037.92
  • Google Android platform running vulnerable Chrome builds
  • Dawn WebGPU implementation embedded in Chromium

Discovery Timeline

  • 2026-09-29 - CVE-2026-102307 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-102307

Vulnerability Analysis

The vulnerability resides in Dawn, the cross-platform WebGPU implementation used by Chromium. Dawn translates WebGPU API calls from web content into native graphics API calls on the underlying platform. On Android, Dawn interacts with Vulkan and other GPU backends to service GPU commands issued by JavaScript.

The defect is classified as an uninitialized resource issue [CWE-908]. Dawn allocates a resource such as a GPU buffer or descriptor without fully initializing its backing memory before making it accessible to the renderer. When the untrusted content later reads this resource, it observes residual bytes from previously freed allocations.

Because GPU memory is often shared with other browser subsystems, the leaked bytes can originate from memory regions holding data outside the WebGPU sandbox. The attacker cannot modify memory or execute code through this flaw. The impact is limited to confidentiality.

Root Cause

The root cause is missing zero-initialization of resource memory in the Dawn WebGPU pipeline before the resource is exposed to JavaScript. This aligns with the CWE-908 pattern where a resource is used before it has been placed into a defined, secure state.

Attack Vector

Exploitation requires a victim to load an attacker-controlled HTML page in a vulnerable Chrome build on Android. The page issues crafted WebGPU calls that allocate a resource and then read back its contents. The returned data contains uninitialized memory bytes that the attacker exfiltrates to a remote endpoint. No authentication or elevated privileges are required.

No public proof-of-concept exploit is listed for this CVE. Technical specifics are tracked in Chromium Issue Tracker #556959073.

Detection Methods for CVE-2026-102307

Indicators of Compromise

  • HTTP requests from Android Chrome clients to domains hosting WebGPU-heavy JavaScript payloads with no legitimate rendering purpose
  • Outbound traffic containing base64-encoded blobs shortly after visits to untrusted sites, consistent with memory exfiltration
  • Chrome crash reports or GPU process anomalies on Android devices browsing unfamiliar pages

Detection Strategies

  • Inventory installed Chrome versions on managed Android devices and flag any build below 154.0.8037.92
  • Inspect mobile device management telemetry for delayed browser updates on corporate-owned Android endpoints
  • Correlate DNS and web proxy logs against threat intelligence feeds that track WebGPU abuse and browser exploit staging sites

Monitoring Recommendations

  • Monitor Chrome update compliance across the Android fleet through enterprise mobility management dashboards
  • Alert on high-entropy outbound payloads from mobile browsers to newly registered domains
  • Track Google Chrome Releases advisories for follow-up Dawn and WebGPU security fixes

How to Mitigate CVE-2026-102307

Immediate Actions Required

  • Update Google Chrome on Android to version 154.0.8037.92 or later through the Google Play Store
  • Push forced browser updates via mobile device management for corporate Android devices
  • Restrict access to untrusted websites from unpatched devices until updates are applied

Patch Information

Google addressed the issue in the Chrome Stable channel update referenced in the Google Chrome Stable Update advisory. Users on Android should install Chrome 154.0.8037.92 or later. The fix initializes Dawn resources before they are exposed to renderer content.

Workarounds

  • Disable WebGPU in Chrome on Android by navigating to chrome://flags and setting the #enable-unsafe-webgpu and WebGPU-related flags to Disabled where available
  • Use an alternative browser on Android until the Chrome update is deployed
  • Enforce web filtering policies that block access to unknown or high-risk domains from mobile endpoints
bash
# Example: enforce minimum Chrome version via Android Enterprise managed configuration
# Managed app configuration key for Chrome
MinimumVersion=154.0.8037.92

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.