CVE-2026-6920
vulnerability analysis and mitigation

Overview

CVE-2026-6920 is an out-of-bounds read vulnerability in the GPU component of Google Chrome on Android, classified as High severity by Chromium's security team. It affects Google Chrome for Android versions prior to 147.0.7727.117, and allows a remote attacker who has already compromised the renderer process to potentially escape the browser sandbox via a crafted HTML page. The vulnerability was reported by tatiwari of Microsoft on 2026-04-06 and publicly disclosed on April 22–23, 2026, when Google released the patched stable channel update. It carries a CVSS v3.1 base score of 9.6 (Critical) per Feedly's assessment, though the GitHub Advisory Database scores it at 7.5 (High) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and resides in Chrome's GPU processing subsystem on Android. An attacker who has already achieved renderer process compromise can trigger an out-of-bounds memory read in the GPU component by delivering a specially crafted HTML page, which can then be leveraged to escape Chrome's sandbox. The attack requires prior renderer compromise as a precondition, meaning it is typically chained with a separate renderer exploitation vulnerability; user interaction (visiting a malicious page) is required to initiate the chain. The Chromium bug tracker entry is issue #499891888, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation enables a sandbox escape on Android devices running vulnerable Chrome versions, allowing an attacker to break out of Chrome's security sandbox and potentially gain unauthorized access to the underlying Android system. The primary impact is high confidentiality loss — sensitive data accessible on the device could be exposed to the attacker. Integrity and availability of the device may also be affected if the sandbox escape is used to execute further malicious actions, such as installing malware or accessing other applications' data (GitHub Advisory, Chrome Releases).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.068–0.094%, placing it in the lower percentiles for near-term exploitation likelihood. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires chaining with a renderer compromise, which raises the bar for attackers but does not eliminate risk given the prevalence of Chrome renderer bugs.

Exploitation steps

  1. Renderer Compromise: The attacker must first exploit a separate vulnerability (e.g., a renderer bug such as a use-after-free or type confusion) to gain code execution within Chrome's renderer process on an Android device running Chrome prior to 147.0.7727.117.
  2. Craft Malicious HTML Page: Prepare a specially crafted HTML page that triggers the out-of-bounds read in Chrome's GPU component, exploiting the improper buffer boundary handling in GPU processing.
  3. Deliver Payload: Lure the target user to visit the malicious page (e.g., via phishing link, malicious ad, or compromised website), satisfying the user interaction requirement.
  4. Trigger OOB Read: The crafted page causes the GPU subsystem to read memory beyond the intended buffer boundaries, leaking or manipulating memory in a way that enables sandbox escape.
  5. Sandbox Escape: Leverage the out-of-bounds read to break out of Chrome's sandbox on Android, gaining access to the broader device environment and potentially executing arbitrary code with elevated privileges (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unusual outbound connections from the Android device to unknown or suspicious IP addresses following Chrome browser activity; unexpected data exfiltration traffic originating from the Chrome process.
  • Process: Unexpected child processes spawned outside of Chrome's normal sandbox boundaries on Android; GPU-related process crashes or abnormal terminations in Chrome logs.
  • Logs: Chrome crash reports or GPU process error logs referencing out-of-bounds memory access; Android system logs showing unusual privilege escalation events associated with the Chrome process.
  • File System: Unexpected files written to directories outside Chrome's sandboxed storage area; new or modified files in sensitive Android system directories following Chrome usage.

Mitigation and workarounds

Google has released a fix in Chrome version 147.0.7727.117 for Android (and 147.0.7727.116/117 for Windows/Mac/Linux). Users should immediately update Google Chrome on all Android devices to version 147.0.7727.117 or later via the Google Play Store. No specific configuration-based workaround has been published; updating to the patched version is the only recommended remediation. Organizations should also consider implementing application allowlisting to restrict Chrome to trusted, up-to-date versions, and monitor for suspicious browser behavior on Android endpoints (Chrome Releases, GitHub Advisory).

Community reactions

Forbes covered the vulnerability as a security alert for Chrome's large user base, framing it as a significant risk for Android users (Forbes). PCWorld reported on the Chrome 147 update as fixing two high-risk security vulnerabilities (PCWorld). The Hacker Wire published a dedicated technical article on the GPU out-of-bounds read and its sandbox escape potential (The Hacker Wire). Microsoft's MSRC also acknowledged the vulnerability, consistent with the fact that the reporter (tatiwari) is a Microsoft researcher. Downstream Linux distributions including Debian, Fedora, and openSUSE issued Chromium security advisories addressing this CVE.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management