Vulnary
← back to the feed
Critical· 9.6official fix available

CVE-2026-9875

A flaw in the WebGL component of Google Chrome on Android allows a remote attacker to read memory outside of its intended boundaries. This vulnerability can be triggered by a specially crafted HTML webpage.

publishedMay 28, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
16th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 20, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of Google Chrome on Android devices running versions prior to 148.0.7778.216.

02

Real-world impact

An attacker could potentially escape the browser's security sandbox, allowing them to gain unauthorized access to parts of the device's system that should be protected.

03

Why this severity

This is rated as critical because it is easy to exploit remotely via a website and can lead to a complete compromise of the browser's security boundaries.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade Google Chrome on Android to version 148.0.7778.216 or later.

NVD-referenced vendor advisory

05

Timeline

  1. May 28, 2026 · May 28, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 14d ago
    Advisory updated
    The NVD record was last revised.
  3. Jul 21, 2026 · 14d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →