Skip to main content
Vulnerability Database/CVE-2026-106370

CVE-2026-106370: Chrome GPU Information Disclosure Flaw

CVE-2026-106370 is an information disclosure vulnerability in Google Chrome GPU on Android that allows attackers to read memory outside the sandbox. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-106370 Overview

CVE-2026-106370 is an uninitialized resource vulnerability [CWE-908] in the GPU component of Google Chrome on Android versions prior to 155.0.8059.39. A remote attacker who has already compromised the renderer process can read memory outside the sandbox by serving a crafted HTML page to the victim. Google's Chromium security team rates the issue as Medium severity.

The flaw does not grant initial code execution. Instead, it serves as a secondary primitive in an exploit chain, enabling information disclosure from protected GPU process memory after an attacker has established a renderer compromise.

Critical Impact

Attackers chaining this bug with a renderer exploit can leak sensitive memory from the GPU process, bypassing the Chrome sandbox boundary on Android devices.

Affected Products

  • Google Chrome for Android versions prior to 155.0.8059.39
  • Chromium-based browsers on Android sharing the vulnerable GPU code path
  • Android applications embedding affected Chromium WebView builds

Discovery Timeline

  • 2026-10-06 - CVE-2026-106370 published to the National Vulnerability Database (NVD)
  • 2026-10-07 - Last updated in the NVD database

Technical Details for CVE-2026-106370

Vulnerability Analysis

The vulnerability resides in Chrome's GPU process on Android. The GPU process handles accelerated rendering, WebGL, and compositor operations on behalf of renderer processes. It runs in a separate address space from renderers as part of Chrome's multi-process sandbox model.

An uninitialized resource flaw [CWE-908] occurs when memory or an object is allocated and used before being populated with defined values. In this case, a renderer process can send crafted IPC messages or WebGL/graphics commands that cause the GPU process to return data from an uninitialized buffer. That data reflects whatever previously resided in that memory region.

Because the GPU process sits outside the renderer sandbox, this grants attackers a cross-boundary read primitive. The leaked contents can include pointers, textures, or other sensitive state useful for defeating Address Space Layout Randomization (ASLR) during subsequent exploit stages.

Root Cause

The root cause is a failure to zero-initialize or validate a GPU resource before its contents are returned across the renderer/GPU process boundary. Chromium issue tracker entry #517033396 documents the specific code path, which Google has restricted while patch adoption completes.

Attack Vector

Exploitation requires two conditions. First, the attacker must already control the renderer process, typically through a separate type confusion or use-after-free bug in V8 or Blink. Second, the victim must load a crafted HTML page in a vulnerable Chrome build on Android. The attacker then issues GPU commands designed to trigger the uninitialized read and exfiltrate the returned bytes back to attacker-controlled JavaScript.

See the Chromium Issue Tracker #517033396 for technical details once Google unrestricts the entry.

Detection Methods for CVE-2026-106370

Indicators of Compromise

  • Android devices running Chrome versions below 155.0.8059.39 after the October 2026 patch release window
  • Unexpected GPU process crashes or renderer-to-GPU IPC anomalies in Chrome crash telemetry
  • Mobile device management (MDM) inventory showing stale Chrome installations on managed Android fleets

Detection Strategies

  • Inventory Chrome and Chromium-based browser versions across managed Android endpoints and flag any build older than 155.0.8059.39
  • Monitor mobile endpoint telemetry for browser exploitation patterns, including anomalous child process behavior and unexpected network beaconing originating from browser contexts
  • Correlate web proxy logs with threat intelligence on exploit kits and watering-hole campaigns targeting Chromium renderer bugs

Monitoring Recommendations

  • Enable centralized crash and telemetry reporting from Android Chrome deployments to surface GPU process anomalies
  • Track the Google Chrome Stable Update channel for follow-on advisories and chained CVEs
  • Alert on devices that fail to apply Play Store updates within defined patch-compliance windows

How to Mitigate CVE-2026-106370

Immediate Actions Required

  • Update Google Chrome on all Android devices to version 155.0.8059.39 or later through the Google Play Store
  • Push patch compliance policies via MDM to enforce browser updates on corporate-managed Android devices
  • Audit any in-house Android applications that embed Chromium WebView and update to a patched build

Patch Information

Google addressed CVE-2026-106370 in the Chrome Stable channel release for Android. Users and administrators should ensure Chrome is updated to 155.0.8059.39 or newer. Details are available in the Google Chrome Stable Update announcement.

Workarounds

  • Restrict browsing on managed Android devices to trusted sites until Chrome is patched
  • Disable hardware acceleration where feasible to reduce exposure of the GPU process attack surface, accepting the performance trade-off
  • Deploy mobile threat defense tooling to detect exploitation attempts originating from malicious web content
bash
# Verify installed Chrome version on an Android device via ADB
adb shell dumpsys package com.android.chrome | grep versionName

# Expected output after patching:
# versionName=155.0.8059.39

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.