CVE-2026-106275 Overview
CVE-2026-106275 is an uninitialized resource vulnerability in the GPU component of Google Chrome on Android. The flaw affects Chrome versions prior to 155.0.8059.39 and permits a remote attacker to read memory outside the sandbox through a crafted HTML page. Chromium rates the underlying security severity as Low, while the assigned CVSS v3.1 base score of 4.7 places it in the Medium range due to the cross-sandbox scope change. The weakness maps to [CWE-908: Use of Uninitialized Resource].
Critical Impact
An attacker who convinces a user to visit a malicious page can read uninitialized GPU memory outside the Chrome sandbox, potentially leaking sensitive data rendered or processed by other origins or system components.
Affected Products
- Google Chrome for Android versions prior to 155.0.8059.39
- Chromium-based GPU process on the Android platform
- Downstream Android browsers embedding the vulnerable Chromium GPU stack
Discovery Timeline
- 2026-10-06 - CVE-2026-106275 published to the National Vulnerability Database
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-106275
Vulnerability Analysis
The vulnerability resides in Chrome's GPU process on Android. The GPU process allocates or references a resource without fully initializing its backing memory. When that resource is subsequently read, residual bytes from prior allocations become observable to code reachable from the renderer.
Because the leak occurs in the GPU process rather than the renderer sandbox, an attacker can obtain memory contents that the renderer should not be able to see. The CVSS vector indicates network reachability, no privileges, user interaction through page navigation, and a scope change reflecting the sandbox boundary crossing.
Confidentiality impact is rated low, with no integrity or availability impact. Google classifies the Chromium security severity as Low. The EPSS probability stands at 0.19% with a percentile of 7.96, indicating limited observed exploitation interest at publication.
Root Cause
The root cause is uninitialized memory use ([CWE-908]) within a GPU resource allocation path. The affected code path exposes resource contents before the memory region is explicitly cleared or populated. Specific function-level details are tracked in Chromium Issue Tracker #514460295.
Attack Vector
Exploitation requires a user to load a crafted HTML page in a vulnerable Chrome build on Android. The page triggers GPU operations that cause the browser to return uninitialized memory bytes to attacker-reachable surfaces, such as WebGL readbacks, canvas pixel reads, or similar GPU-backed APIs. No authentication or elevated privileges are required. Refer to the Google Chrome Stable Update advisory and the Chromium issue tracker for additional technical context.
Detection Methods for CVE-2026-106275
Indicators of Compromise
- Mobile devices running Chrome for Android with version strings below 155.0.8059.39
- Outbound requests from mobile browsers to pages invoking heavy WebGL, WebGPU, or canvas readback operations followed by data exfiltration to attacker-controlled domains
- Crash or sandbox telemetry originating from the Chrome GPU process on Android endpoints
Detection Strategies
- Inventory installed Chrome versions on managed Android devices and flag builds older than 155.0.8059.39
- Monitor mobile threat defense telemetry for browsing sessions to URLs flagged as hosting exploit kits or GPU-abuse proof-of-concepts
- Correlate browser crash reports with visits to untrusted domains to identify attempted exploitation of GPU memory
Monitoring Recommendations
- Enable centralized Chrome update reporting through Google Admin or enterprise mobility management platforms
- Track Chrome Releases advisories and automate alerts when stable channel updates reference GPU or sandbox issues
- Review web gateway logs for repeated access to pages serving unusual WebGL or WebGPU payloads from new or low-reputation domains
How to Mitigate CVE-2026-106275
Immediate Actions Required
- Update Google Chrome for Android to version 155.0.8059.39 or later through the Google Play Store
- Push the updated Chrome build to managed devices via enterprise mobility management tooling
- Verify downstream Android browsers that embed Chromium have incorporated the corresponding GPU fix
Patch Information
Google addressed the issue in the Chrome Stable channel release documented in the Google Chrome Stable Update advisory. The fix is included in Chrome 155.0.8059.39 and later. Tracking details are available in Chromium Issue Tracker #514460295.
Workarounds
- Restrict browsing to trusted sites until all managed Android devices receive the patched Chrome build
- Deploy mobile web filtering to block categories commonly used to host exploit content
- Advise users to avoid clicking links from untrusted sources on Android devices still running vulnerable Chrome builds
# Verify Chrome for Android version via adb
adb shell dumpsys package com.android.chrome | grep versionName
# Expected output: versionName=155.0.8059.39 or later
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.