CVE-2026-16424
Description
Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
In plain language
AI Worth attentionCVE-2026-16424 is a serious Google Chrome on Android bug where, after an attacker already takes over Chrome’s renderer, they may escape Chrome’s safety barriers; most small businesses are only affected if your devices are running an old Chrome version and are exposed to hostile content.
CVE-2026-16424 is a use-after-free in the GPU component of Google Chrome on Android prior to 150.0.7871.182, where a remote attacker who has already compromised the renderer process may use it to escape the sandbox.
What to do now
- Check which Google Chrome version is installed on your Android devices.
- Confirm whether any users can open untrusted web content (links, emails, web pages) on those devices.
- Update Google Chrome on Android to 150.0.7871.182 or later.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-16424 and every CVE in our database. Create a free account — no credit card required.
Create Free Account