Skip to main content
Vulnerability Database/CVE-2026-95322

CVE-2026-95322: Google Chrome GPU RCE Vulnerability

CVE-2026-95322 is a critical remote code execution vulnerability in Google Chrome GPU on Android that allows attackers to escape the sandbox and execute arbitrary code. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-95322 Overview

CVE-2026-95322 is an out-of-bounds write vulnerability [CWE-787] in the GPU component of Google Chrome on Android. The flaw affects versions prior to 154.0.8037.57. A remote attacker who has already compromised the renderer process can execute arbitrary code outside the Chrome sandbox by serving a crafted HTML page. Chromium's security team rated the underlying issue Critical, while the CVSS Base Score is 8.3. Successful exploitation breaks the sandbox boundary, one of Chrome's core defense-in-depth mechanisms on mobile.

Critical Impact

Sandbox escape leading to arbitrary code execution on Android devices running vulnerable Chrome builds.

Affected Products

  • Google Chrome on Android versions prior to 154.0.8037.57
  • Google Android (as the host operating system for the affected Chrome builds)
  • Chromium-derived Android browsers that share the vulnerable GPU code path

Discovery Timeline

  • 2026-09-29 - CVE-2026-95322 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-95322

Vulnerability Analysis

The vulnerability is an out-of-bounds write in Chrome's GPU process on Android. The GPU process handles rendering commands forwarded from lower-privileged renderer processes. Because it runs at a higher privilege level and holds direct access to graphics drivers, memory corruption there translates into code execution outside the renderer sandbox. Exploitation requires the attacker to first compromise the renderer, typically by chaining a separate renderer bug delivered through a crafted HTML page. The final stage escapes the sandbox by writing past the bounds of a GPU-side buffer, corrupting adjacent memory used by the GPU process.

Root Cause

The issue is classified under [CWE-787: Out-of-bounds Write]. A GPU code path writes to a buffer without validating that the target offset or length fits within the allocation. On Android, this results in corruption of process memory in the GPU service, which can be shaped into a control-flow hijack.

Attack Vector

The attack vector is network-based and requires user interaction, such as visiting a malicious page or a compromised site delivering attacker-controlled content. It also depends on a prior renderer compromise, raising exploitation complexity. The scope is changed because impact extends beyond the renderer sandbox into the GPU process. Refer to the Chromium Issue Tracker #556576992 for technical details as they are released.

No public proof-of-concept exploit is available at this time.

Detection Methods for CVE-2026-95322

Indicators of Compromise

  • Chrome for Android crashes originating in the GPU process with signatures consistent with heap or buffer corruption.
  • Unexpected child processes or code execution spawned from the Chrome GPU service context on Android endpoints.
  • Outbound connections from mobile browser processes to previously unseen infrastructure immediately after loading a specific page.

Detection Strategies

  • Inventory managed Android devices and flag Chrome installations below 154.0.8037.57 using MDM or UEM telemetry.
  • Monitor Android crash reporting for repeated GPU-process faults associated with browsing activity.
  • Correlate web proxy or DNS logs with device browsing events to identify users directed to suspicious HTML payloads.

Monitoring Recommendations

  • Ingest mobile browser version telemetry into the SIEM and alert on devices lagging behind the fixed Chrome build.
  • Track threat intelligence feeds for public proof-of-concept code targeting the Chromium GPU process on Android.
  • Review MDM compliance dashboards on a recurring cadence until all managed Android devices are patched.

How to Mitigate CVE-2026-95322

Immediate Actions Required

  • Update Google Chrome on Android to 154.0.8037.57 or later through the Google Play Store.
  • Push a forced update policy for managed Android devices using MDM controls.
  • Restrict browsing to trusted destinations on devices that cannot be patched immediately.

Patch Information

Google addressed the issue in the Chrome Stable channel update referenced in the Chrome Stable Channel Update. Users running Chrome on Android should upgrade to version 154.0.8037.57 or later. Chromium-derived browsers should adopt the corresponding upstream fix once released.

Workarounds

  • No vendor-supplied workaround exists; upgrading Chrome is the supported remediation path.
  • Where patching is delayed, limit use of the affected browser and route mobile web traffic through inspection proxies that can block known malicious payloads.
  • Enforce the principle of least privilege on managed Android devices to reduce the impact of a successful sandbox escape.
bash
# Verify Chrome version on a managed Android device via ADB
adb shell dumpsys package com.android.chrome | grep versionName

# Expected output should show 154.0.8037.57 or higher

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.