Critical· 9.6official fix available
CVE-2026-9875
A flaw in the WebGL component of Google Chrome on Android allows a remote attacker to read memory outside of its intended boundaries. This vulnerability can be triggered by a specially crafted HTML webpage.
publishedMay 28, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
16th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026
An official fix is available, so this entry is kept for 30 days and then removed automatically.
01
Who is affected
Users of Google Chrome on Android devices running versions prior to 148.0.7778.216.
02
Real-world impact
An attacker could potentially escape the browser's security sandbox, allowing them to gain unauthorized access to parts of the device's system that should be protected.
03
Why this severity
This is rated as critical because it is easy to exploit remotely via a website and can lead to a complete compromise of the browser's security boundaries.
04
What to do about it
official fix available
recommended steps
- 01Upgrade Google Chrome on Android to version 148.0.7778.216 or later.
NVD-referenced vendor advisory
05
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
06
How it’s attacked
Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07
References & advisories
- chromereleases.googleblog.com/2026/05/stable-channel-upda…release notes
- issues.chromium.org/issues/507508103permissions required
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →