Skip to main content
Vulnerability Database/CVE-2026-106290

CVE-2026-106290: Chrome Android GPU Information Disclosure

CVE-2026-106290 is an information disclosure vulnerability affecting the GPU component in Google Chrome on Android versions prior to 155.0.8059.39. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-106290 Overview

CVE-2026-106290 is an uninitialized resource vulnerability in the GPU component of Google Chrome on Android. The flaw affects versions prior to 155.0.8059.39 and is classified under [CWE-908: Use of Uninitialized Resource]. A remote attacker who has already compromised the renderer process can read memory outside the Chrome sandbox by serving a crafted HTML page. Google Chromium rates the severity as Medium. The vulnerability requires user interaction, since the victim must load the attacker-controlled page in a vulnerable browser.

Critical Impact

An attacker who has compromised the renderer can read memory outside the sandbox boundary, exposing sensitive data from the GPU process on Android devices.

Affected Products

  • Google Chrome on Android prior to version 155.0.8059.39
  • Chromium-based browsers on Android inheriting the vulnerable GPU code path
  • Android applications embedding affected Chromium WebView builds

Discovery Timeline

  • 2026-10-06 - CVE-2026-106290 published to NVD
  • 2026-10-07 - Last updated in NVD database

Technical Details for CVE-2026-106290

Vulnerability Analysis

The vulnerability resides in the GPU process of Chrome on Android. The GPU process allocates or references a resource without initializing its contents before use. When the renderer process interacts with this resource through standard inter-process communication, uninitialized memory contents are returned across the sandbox boundary. This behavior lets an attacker who already controls the renderer process extract data from the GPU process address space. The GPU process runs with broader privileges than the sandboxed renderer, so leaked memory may include graphics buffers, texture data, or pointers useful for further exploitation.

Root Cause

The root cause is a missing initialization step for a GPU resource before it is exposed to the renderer. [CWE-908] describes this class of defect, where the program reads from a resource that has not been properly set to a known value. In Chromium, GPU buffers and shared memory regions must be zeroed or explicitly populated before being handed back to a less-privileged process. The absence of this step allows residual data from prior allocations to be observed.

Attack Vector

Exploitation requires two conditions. First, the attacker must already have compromised the renderer process, typically through a separate renderer bug. Second, the victim must load a crafted HTML page that exercises the vulnerable GPU code path. The resulting information disclosure facilitates sandbox escape chains by revealing memory layout details or sensitive content from the GPU process. Refer to the Chromium Issue Tracker #507351786 and Chrome Release Update for upstream details.

Detection Methods for CVE-2026-106290

Indicators of Compromise

  • Android devices running Chrome versions earlier than 155.0.8059.39 after the patch release date
  • Unexpected GPU process crashes or memory anomalies on Android Chrome clients
  • Renderer processes issuing unusual GPU command sequences from recently visited untrusted pages

Detection Strategies

  • Inventory browser versions across managed Android fleets and flag devices below 155.0.8059.39
  • Monitor web proxy and DNS telemetry for navigation to suspicious or newly registered domains serving WebGL or Canvas-heavy content
  • Correlate renderer compromise indicators with subsequent GPU process anomalies to identify chained exploitation attempts

Monitoring Recommendations

  • Enable mobile browser version reporting through enterprise mobility management (EMM) tooling
  • Collect Chrome crash telemetry on Android to identify abnormal GPU process termination patterns
  • Review threat intelligence feeds for public proof-of-concept activity associated with CVE-2026-106290

How to Mitigate CVE-2026-106290

Immediate Actions Required

  • Update Google Chrome on Android to version 155.0.8059.39 or later through the Google Play Store
  • Push the updated Chrome version to managed Android devices using mobile device management (MDM) policies
  • Audit Android applications using WebView components and update to patched Chromium builds

Patch Information

Google addressed the issue in Chrome for Android version 155.0.8059.39. The fix initializes the affected GPU resource before it crosses the sandbox boundary. Patch details and the stable channel announcement are available in the Chrome Release Update. The underlying code change is referenced in Chromium Issue Tracker #507351786.

Workarounds

  • Restrict browsing on unmanaged Android devices to trusted sites until the Chrome update is deployed
  • Use enterprise policies to disable WebGL or GPU acceleration where business requirements allow, reducing exposure of the vulnerable GPU path
  • Enforce safe browsing protections and site isolation settings through Chrome enterprise policy
bash
# Verify installed Chrome version on an Android device via adb
adb shell dumpsys package com.android.chrome | grep versionName

# Expected output after patching:
# versionName=155.0.8059.39 (or later)

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.