CVE-2026-95332 Overview
CVE-2026-95332 is a memory disclosure vulnerability in the Tint component of Google Chrome on Android. Tint is the WebGPU shader language compiler used by Chromium. The flaw stems from use of an uninitialized variable [CWE-457] and allows a remote attacker to read memory outside the sandbox through a crafted HTML page. Google fixed the issue in Chrome 154.0.8037.57 for Android. Chromium classifies the security severity as Medium.
Critical Impact
A remote attacker can read process memory outside the renderer sandbox by luring a user to a crafted HTML page, exposing sensitive data from the browser process.
Affected Products
- Google Chrome for Android prior to 154.0.8037.57
- Google Android devices running vulnerable Chrome builds
- Chromium-based components that bundle the affected Tint version
Discovery Timeline
- 2026-09-29 - CVE-2026-95332 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-95332
Vulnerability Analysis
The defect resides in Tint, the shader compiler and translator used by Chromium's WebGPU implementation. Tint parses WebGPU Shading Language (WGSL) supplied by web content and lowers it into backend shader forms. A code path in Tint uses a variable before it is initialized, allowing residual memory contents to leak into observable state.
Because WebGPU is reachable from any origin over the network, a crafted HTML page can trigger the vulnerable path without prior authentication. Successful exploitation returns memory outside the sandbox boundary that Chrome uses to isolate untrusted web content. The result is confidentiality loss rather than code execution or process compromise.
Root Cause
The root cause is a missing initialization of a variable inside Tint prior to its first read. When the compiler consumes attacker-controlled WGSL, the uninitialized storage is consulted, and its contents are propagated into a channel the caller can observe. This class of defect is tracked as CWE-457: Use of Uninitialized Variable.
Attack Vector
Exploitation requires a victim to load attacker-controlled HTML in a vulnerable Chrome build on Android. The page uses WebGPU to submit crafted WGSL that reaches the flawed Tint code path. No credentials or elevated privileges are required, and the flaw crosses the renderer sandbox to disclose memory the renderer should not observe.
No public proof-of-concept exploit is listed in the referenced advisories, and the issue is not present on the CISA Known Exploited Vulnerabilities list. Technical detail is tracked in Chromium Issue Tracker #546639650.
Detection Methods for CVE-2026-95332
Indicators of Compromise
- Android devices reporting Chrome versions earlier than 154.0.8037.57 in mobile device management (MDM) inventory.
- Outbound requests from mobile browsers to unfamiliar domains that serve pages invoking WebGPU (navigator.gpu) and issuing WGSL shader modules.
- Web filtering logs showing repeated visits to pages hosting large or obfuscated WGSL payloads.
Detection Strategies
- Inventory installed Chrome builds on Android fleets and compare against the fixed version 154.0.8037.57.
- Correlate browser telemetry with URL categorization to flag WebGPU-heavy pages loaded from uncategorized or newly registered domains.
- Alert on Android application version drift where Chrome auto-update is disabled or blocked by policy.
Monitoring Recommendations
- Track Chrome release notes through the Google Chrome Stable Update advisory and enforce mobile update SLAs.
- Monitor MDM compliance dashboards for devices that fail to reach the patched Chrome build within the defined window.
- Log DNS and TLS SNI data from mobile egress to identify visits to crafted HTML lure domains.
How to Mitigate CVE-2026-95332
Immediate Actions Required
- Update Google Chrome on Android to version 154.0.8037.57 or later through Google Play.
- Enforce Chrome auto-update on managed Android devices via MDM configuration.
- Restrict access to untrusted web content on high-value mobile devices until patching completes.
Patch Information
Google fixed CVE-2026-95332 in Chrome 154.0.8037.57 for Android. Details are published in the Google Chrome Stable Update advisory. The underlying code change is referenced in Chromium Issue Tracker #546639650.
Workarounds
- Avoid browsing untrusted sites on Android Chrome builds earlier than 154.0.8037.57.
- Disable WebGPU on managed browsers by configuring the Chrome enterprise policy that controls the WebGPU feature until devices are patched.
- Use network filtering to block newly observed or uncategorized domains that serve WebGPU content to mobile users.
# Verify Chrome version on an Android device via ADB
adb shell dumpsys package com.android.chrome | grep versionName
# Expected output on a patched device
# versionName=154.0.8037.57
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.