CVE-2026-95359 Overview
CVE-2026-95359 is an uninitialized resource vulnerability [CWE-908] in the GPU component of Google Chrome on Android. The flaw affects Chrome versions prior to 154.0.8037.57. A remote attacker who has already compromised the renderer process can read memory outside the sandbox by serving a crafted HTML page. Successful exploitation exposes small amounts of process memory that may contain sensitive data useful for chaining further attacks. Google assigned this issue a Chromium security severity rating of Medium.
Critical Impact
An attacker who controls a compromised renderer can leak memory contents outside the Chrome sandbox on Android devices, aiding sandbox escape chains.
Affected Products
- Google Chrome for Android prior to 154.0.8037.57
- Google Android platforms running vulnerable Chrome builds
- Chromium-derived browsers on Android using the affected GPU code path
Discovery Timeline
- 2026-09-29 - CVE-2026-95359 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-95359
Vulnerability Analysis
The vulnerability resides in the GPU process of Chrome on Android. GPU code paths allocate a resource but fail to fully initialize its backing memory before the resource is returned to a caller across the sandbox boundary. When a renderer process reads back that resource, it receives residual bytes from previously used memory. The leaked bytes originate from the GPU process address space, which is not accessible to the renderer sandbox under normal conditions.
Exploitation requires a compromised renderer, meaning the attacker must already control a renderer process through a separate flaw. User interaction is also required, typically loading a crafted HTML page. Because the leak is bounded by the size of the uninitialized allocation, the disclosed information is limited in scope but can include pointers, session data, or content from other origins that transited GPU memory.
Root Cause
The root cause is missing initialization of a GPU resource buffer before it is exposed to a renderer client [CWE-908]. Chromium's shared memory and GPU command buffer model relies on producers zeroing or fully populating resources before handoff. When that contract is violated, uninitialized bytes are readable by lower-privileged processes.
Attack Vector
The attack proceeds in two stages. First, the attacker exploits an unrelated flaw to compromise the renderer process. Second, the attacker uses crafted HTML and JavaScript to invoke the vulnerable GPU code path, then reads back the uninitialized buffer. See the Chromium Issue Tracker #513162143 for additional technical context.
No verified public proof-of-concept code is available for this issue.
Detection Methods for CVE-2026-95359
Indicators of Compromise
- Android devices running Chrome versions earlier than 154.0.8037.57 after the patch release date
- Unexpected renderer process crashes preceding GPU process anomalies in Chrome crash telemetry
- Managed browser fleets reporting outdated Chrome version strings via mobile device management (MDM) inventory
Detection Strategies
- Query MDM and enterprise browser management consoles for Chrome for Android build versions below 154.0.8037.57
- Correlate renderer compromise indicators, such as prior Chrome vulnerabilities being exploited, with subsequent GPU process activity
- Monitor Google Play Store update compliance reports for Chrome updates on managed Android endpoints
Monitoring Recommendations
- Enroll Android devices in mobile threat defense tooling that reports installed browser versions
- Track advisories from the Google Chrome Releases blog for follow-on GPU issues
- Baseline expected Chrome versions across the fleet and alert on drift beyond a defined patch window
How to Mitigate CVE-2026-95359
Immediate Actions Required
- Update Chrome for Android to version 154.0.8037.57 or later through the Google Play Store
- Enforce automatic updates for Chrome on all managed Android endpoints via MDM policy
- Audit the mobile browser inventory to confirm no devices remain on vulnerable builds
Patch Information
Google released the fix in Chrome 154.0.8037.57 for Android. Refer to the Google Chrome Desktop Update advisory and Chromium Issue Tracker #513162143 for release details. The patch initializes the affected GPU resource before it is returned across the sandbox boundary.
Workarounds
- Restrict use of Chrome on Android to trusted sites until the update is applied
- Deploy mobile browser isolation or alternative browsers on high-risk devices pending patching
- Combine with existing renderer-hardening controls, since exploitation requires a prior renderer compromise
# Example MDM compliance check for Chrome version on Android
# Verify installed Chrome build meets minimum patched version
adb shell dumpsys package com.android.chrome | grep versionName
# Expected output should show versionName=154.0.8037.57 or higher
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.