Google Chrome for Android WebGL Use-After-Free Remote Code Execution (CVE-2026-84352)

Release Date: 2nd September 2026 (Added 9 September 2026)

Impact : CRITICAL

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to all users of Google Chrome for Android, including Organizations, System/Network administrators, and members of the general public who browse the web on an Android device. This alert is intended to be understood by both technical and general readers.

What is it?

CVE-2026-84352 is a critical use-after-free vulnerability in the WebGL component of Google Chrome for Android, allowing a remote attacker to execute arbitrary code outside Chrome's sandbox simply by getting a victim to open a specially crafted HTML page.

CERTVU independently confirmed via Google's own Chrome Releases blog that the fix is available in Chrome 152.0.7977.75 and later for Android.

Reference

  1. https://www.cve.org/CVERecord?id=CVE-2026-84352
  2. https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html