Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79008

CVE-2026-79008: Google Chrome GPU RCE Vulnerability

CVE-2026-79008 is a remote code execution vulnerability in Google Chrome GPU on Android that enables attackers to escape the sandbox and execute arbitrary code. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-79008 Overview

CVE-2026-79008 is an improper input validation vulnerability [CWE-20] in the GPU component of Google Chrome on Android. The flaw affects Chrome versions prior to 152.0.7977.65. A remote attacker who has already compromised the renderer process can leverage a crafted HTML page to execute arbitrary code outside the Chrome sandbox. Google classified this as a sandbox escape scenario, which elevates its impact well beyond a typical renderer bug.

Critical Impact

Successful exploitation breaks out of the Chrome sandbox on Android, allowing arbitrary code execution in a more privileged context and undermining the browser's primary isolation boundary.

Affected Products

  • Google Chrome for Android prior to 152.0.7977.65
  • Google Android devices running vulnerable Chrome builds
  • Any Chromium-based Android application sharing the affected GPU code path

Discovery Timeline

  • 2026-08-25 - CVE-2026-79008 published to the National Vulnerability Database
  • 2026-08-27 - Last updated in NVD database

Technical Details for CVE-2026-79008

Vulnerability Analysis

The vulnerability resides in Chrome's GPU process on Android. The GPU process handles rendering commands issued by the lower-privileged renderer process and traditionally sits on a stronger side of the sandbox boundary. Improper input validation in this component allows a compromised renderer to submit malformed data that the GPU process fails to sanitize.

Because the GPU process on Android runs with broader access to graphics drivers and system resources, corrupting its state provides a path out of the renderer sandbox. Chromium tracks the underlying issue as Chromium Issue #517382613. Google labeled the Chromium security severity as Medium, while the NVD scoring reflects the higher end-to-end impact when chained with a renderer compromise.

Root Cause

The root cause is missing or insufficient validation of inputs passed into the GPU process from the renderer over Chrome's inter-process communication (IPC) channels. When crafted HTML triggers specific GPU commands, the unvalidated data reaches code paths that assume well-formed input. The resulting memory or state corruption is usable for code execution in the GPU process context.

Attack Vector

Exploitation requires the attacker to first compromise the renderer process, typically through a separate renderer bug or a web-exposed vulnerability. Once inside the renderer, the attacker serves a crafted HTML page that issues malicious GPU commands. User interaction is required, consistent with normal browsing activity. The attack completes when the malformed input reaches the vulnerable GPU code path and escapes the sandbox.

No public proof-of-concept or exploit is listed in Exploit-DB, and the vulnerability is not on the CISA Known Exploited Vulnerabilities catalog. See the Google Chrome Stable Update announcement for vendor details.

Detection Methods for CVE-2026-79008

Indicators of Compromise

  • Unexpected crashes or restarts of the Chrome GPU process on Android endpoints
  • Chrome child processes spawning shell utilities or writing to unusual paths
  • Outbound connections from Chrome to attacker-controlled domains immediately after page loads
  • Android application logs showing anomalous WebView or Chromium GPU service faults

Detection Strategies

  • Inventory Chrome for Android versions across managed devices and flag builds below 152.0.7977.65
  • Monitor mobile threat telemetry for browser process anomalies and post-exploitation behaviors
  • Correlate crash telemetry with web navigation logs to identify pages that consistently destabilize the GPU process
  • Hunt for renderer-to-GPU exploit chains by reviewing Chromium crash dumps against the fixed-version baseline

Monitoring Recommendations

  • Enforce mobile device management (MDM) reporting on Chrome version compliance
  • Aggregate Android endpoint telemetry into a central data lake for cross-device correlation
  • Alert on privilege changes or new persistence artifacts following Chrome usage
  • Track outbound network activity from Android endpoints against threat intelligence feeds

How to Mitigate CVE-2026-79008

Immediate Actions Required

  • Update Chrome for Android to version 152.0.7977.65 or later through the Google Play Store
  • Push forced updates via MDM to any device that has not upgraded automatically
  • Restrict use of unmanaged Chromium-based browsers on corporate Android devices until patched
  • Advise users to avoid untrusted links and sites until fleet-wide patch compliance is confirmed

Patch Information

Google addressed CVE-2026-79008 in Chrome 152.0.7977.65 on the stable channel. Details are published in the Chrome Stable Channel Update. Administrators should verify installed versions on managed Android devices and confirm rollout completion.

Workarounds

  • No vendor-supplied workaround exists; upgrading to the fixed version is the only complete mitigation
  • Where patching is delayed, use MDM policy to restrict Chrome to trusted internal sites
  • Consider temporarily disabling GPU-accelerated rendering flags on high-risk devices, accepting the performance tradeoff
  • Increase user awareness training about opening untrusted links on Android devices
bash
# Configuration example: verify Chrome version on Android via adb
adb shell dumpsys package com.android.chrome | grep versionName

# Force-update Chrome through Managed Google Play (example gcloud command)
gcloud beta mobile android apps update \
  --package-name com.android.chrome \
  --min-version 152.0.7977.65

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.