
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-6920 is an out-of-bounds read vulnerability in the GPU component of Google Chrome on Android, classified as High severity by Chromium's security team. It affects Google Chrome for Android versions prior to 147.0.7727.117, and allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox via a crafted HTML page. The vulnerability was reported by tatiwari of Microsoft on 2026-04-06 and publicly disclosed on April 22–23, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 9.6 (Critical) per Feedly's assessment, though the GitHub Advisory Database scores it at 7.5 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's GPU processing subsystem on Android. An attacker who has already achieved renderer process compromise can trigger an out-of-bounds memory read in the GPU component by delivering a specially crafted HTML page, which can then be leveraged to escape Chrome's sandbox. The attack requires prior renderer compromise as a precondition, meaning it is typically chained with a separate renderer exploitation vulnerability; user interaction (visiting a malicious page) is required to initiate the chain. The Chromium bug tracker entry is issue #499891888, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).
Successful exploitation enables a sandbox escape on Android devices running vulnerable Chrome versions, allowing an attacker to break out of Chrome's security sandbox and potentially gain unauthorized access to the underlying Android system. The primary impact is high confidentiality loss — sensitive data accessible on the device could be exposed to the attacker. Integrity and availability of the device may also be affected if the sandbox escape is used to execute further malicious actions, such as installing malware or accessing other applications' data (GitHub Advisory, Chrome Releases).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.068–0.094%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires chaining with a renderer compromise, which raises the bar for attackers but does not eliminate risk given the prevalence of Chrome renderer bugs.
Google has released a fix in Chrome version 147.0.7727.117 for Android (and 147.0.7727.116/117 for Windows/Mac/Linux). Users should immediately update Google Chrome on all Android devices to version 147.0.7727.117 or later via the Google Play Store. No specific configuration-based workaround has been published; updating to the patched version is the only recommended remediation. Organizations should also consider implementing application allowlisting to restrict Chrome to trusted, up-to-date versions, and monitor for suspicious browser behavior on Android endpoints (Chrome Releases, GitHub Advisory).
Forbes covered the vulnerability as a security alert for Chrome's large user base, framing it as a significant risk for Android users (Forbes). PCWorld reported on the Chrome 147 update as fixing two high-risk security vulnerabilities (PCWorld). The Hacker Wire published a dedicated technical article on the GPU out-of-bounds read and its sandbox escape potential (The Hacker Wire). Microsoft's MSRC also acknowledged the vulnerability, consistent with the fact that the reporter (tatiwari) is a Microsoft researcher. Downstream Linux distributions including Debian, Fedora, and openSUSE issued Chromium security advisories addressing this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."