
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4439 is an out-of-bounds memory access vulnerability in the WebGL component of Google Chrome on Android. It allows a remote attacker to potentially perform a sandbox escape via a crafted HTML page, requiring only user interaction (visiting the malicious page). The vulnerability affects Google Chrome versions prior to 146.0.7680.153 on Android and was reported by researcher "Goodluck" on January 15, 2026, with the patch released on March 18, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Red Hat Bugzilla).
The vulnerability is rooted in improper memory handling within Chrome's WebGL implementation on Android, classified under CWE-787 (Out-of-bounds Write) and CWE-125 (Out-of-bounds Read). An attacker can craft a malicious HTML page that triggers out-of-bounds memory access when processed by the WebGL subsystem, potentially enabling a sandbox escape. Exploitation requires no special privileges but does require the victim to visit an attacker-controlled page. The Chromium issue tracker references bug ID 475877320, though full technical details remain restricted pending broad user patching (Chrome Releases, Red Hat Bugzilla).
Successful exploitation could allow a remote attacker to escape Chrome's security sandbox on Android devices, potentially enabling arbitrary code execution with elevated permissions on the underlying system. This represents a full compromise of confidentiality, integrity, and availability of the affected device. The attack surface is broad given Chrome's widespread use on Android, and a successful sandbox escape could facilitate further device compromise, data theft, or installation of malware (Chrome Releases, Red Hat Bugzilla).
Google has released a fix in Chrome version 146.0.7680.153 (Linux/Android) and 146.0.7680.153/154 (Windows/Mac). Users on Android should update Chrome immediately via the Google Play Store. As an interim measure, organizations should consider restricting access to untrusted or unknown websites on Android devices until patching is complete. Downstream distributions including Debian, Fedora, and openSUSE have also released updated Chromium packages (Chrome Releases, Red Hat Bugzilla).
The vulnerability was covered by multiple security news outlets including Heise, GBHackers, CyberSecurityNews, and PCWorld, all highlighting the broader Chrome 146 update that patched 26 vulnerabilities including three rated Critical. The Hacker News included it in their weekly security recap. Coverage generally emphasized the urgency of updating Chrome on Android given the sandbox escape potential (Heise, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."