Skip to main content
Vulnerability Database/CVE-2026-95357

CVE-2026-95357: Google Chrome GPU RCE Vulnerability

CVE-2026-95357 is a critical remote code execution flaw in Google Chrome GPU on Android that enables attackers to execute arbitrary code outside the sandbox. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-95357 Overview

CVE-2026-95357 is an out-of-bounds write vulnerability in the GPU component of Google Chrome on Android. The flaw affects Chrome versions prior to 154.0.8037.57 and is tracked under [CWE-787]. A remote attacker can serve a crafted HTML page that triggers memory corruption in the GPU process, potentially executing arbitrary code outside the browser sandbox. Google's Chromium team rated the underlying issue as Critical severity. Exploitation requires user interaction, specifically visiting a malicious page in a vulnerable Chrome build.

Critical Impact

Successful exploitation allows arbitrary code execution outside the Chrome sandbox on Android devices, providing an attacker with expanded access to the underlying operating system.

Affected Products

  • Google Chrome for Android prior to 154.0.8037.57
  • Google Android devices running vulnerable Chrome builds
  • Chromium-based components sharing the affected GPU code path

Discovery Timeline

  • 2026-09-29 - CVE-2026-95357 published to the National Vulnerability Database (NVD)
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-95357

Vulnerability Analysis

The vulnerability is an out-of-bounds write [CWE-787] in Chrome's GPU process on Android. The GPU process handles rendering, WebGL, and hardware-accelerated compositing, and it interacts with device drivers through privileged interfaces. Writing past the bounds of an allocated buffer inside this process corrupts adjacent memory, which an attacker can shape to hijack control flow. Because the GPU process runs with broader access than the renderer sandbox, code execution here escapes typical renderer isolation. The attack is delivered over the network through a crafted HTML page, and the user must load that page in the vulnerable Chrome build.

Root Cause

The root cause is missing or incorrect boundary checks when the GPU process handles attacker-controlled input from a rendered page. Specific implementation details are restricted in the Chromium Issue Tracker #530045332 while patch adoption progresses. The condition falls into the same class as prior Chrome GPU memory-safety issues, where malformed graphics commands or buffer descriptors drive a write beyond an allocated region.

Attack Vector

Exploitation proceeds over the network with user interaction. An attacker hosts a crafted HTML page that issues GPU workloads via JavaScript, WebGL, or related graphics APIs. When a user opens the page in a vulnerable Chrome build on Android, the malicious payload triggers the out-of-bounds write inside the GPU process. Chained with a suitable memory disclosure primitive, the write enables arbitrary code execution outside the renderer sandbox. Drive-by delivery through malvertising, phishing links, or compromised sites is the expected distribution method.

No public proof-of-concept is available at the time of publication. See the Google Chrome Stable Update advisory for release notes.

Detection Methods for CVE-2026-95357

Indicators of Compromise

  • Chrome for Android GPU process crashes or unexpected restarts correlated with browsing activity
  • Outbound connections from Android devices to unfamiliar domains immediately after page loads containing heavy WebGL or canvas content
  • Chrome version strings below 154.0.8037.57 reported by mobile device management (MDM) inventory

Detection Strategies

  • Inventory Chrome versions across managed Android fleets and flag builds earlier than 154.0.8037.57
  • Correlate Chrome crash telemetry from Android with URL browsing history to identify pages triggering GPU faults
  • Apply network detections for known malicious domains distributing browser exploit kits targeting Chromium GPU flaws

Monitoring Recommendations

  • Ingest mobile browser telemetry and MDM compliance data into a centralized analytics platform for version tracking
  • Alert on repeated Chrome renderer or GPU process termination events on the same device within short time windows
  • Monitor for post-exploitation behavior on Android, including unexpected process launches, privilege changes, or new persistence entries

How to Mitigate CVE-2026-95357

Immediate Actions Required

  • Update Google Chrome on Android to version 154.0.8037.57 or later through the Google Play Store
  • Force-push the updated Chrome build using enterprise mobility management where user-driven updates are unreliable
  • Audit Android device inventories to confirm no user is running a pre-patch Chrome release

Patch Information

Google addressed the issue in Chrome 154.0.8037.57 for Android. Refer to the Google Chrome Stable Update advisory for release details and to the restricted Chromium Issue Tracker #530045332 entry for issue metadata. Apply the update across all managed Android endpoints as the primary remediation.

Workarounds

  • Restrict browsing to trusted sites until the Chrome update is installed on all Android devices
  • Use an alternative up-to-date browser on Android where Chrome cannot be updated immediately
  • Block known malicious domains and exploit-kit infrastructure at the network egress or DNS layer
bash
# Verify Chrome version on a managed Android device via adb
adb shell dumpsys package com.android.chrome | grep versionName

# Expected output for a patched device:
# versionName=154.0.8037.57

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.