CVE-2026-9876: Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to po...
Use after free in WebGL in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
This is a critical Chrome on Android vulnerability in WebGL. A malicious web page could potentially let an attacker escape Chrome’s sandbox, which raises the business risk beyond a normal browser crash or tab compromise. The bundle does not show active exploitation, but the severity and browser exposure make patch verification urgent.
Executive priority
Treat this as urgent patch governance for Android endpoints, not a server incident. The main decision is whether all business Android devices can be verified as updated quickly, especially users with sensitive access.
Technical view
CVE-2026-9876 is a CWE-416 use-after-free in WebGL affecting Google Chrome on Android before 148.0.7778.216. CVSS is 9.6 with network attack vector, low complexity, no privileges, required user interaction, changed scope, and high confidentiality, integrity, and availability impact.
Likely exposure
Organizations are most likely exposed through managed or unmanaged Android devices running Chrome earlier than 148.0.7778.216 and visiting untrusted or compromised web pages. The source bundle identifies Chrome on Android only; it does not substantiate other affected products.
Exploitation context
The source says a remote attacker could potentially perform a sandbox escape through a crafted HTML page. User interaction is required. The bundle marks KEV as false and provides no cited evidence of active exploitation or public exploit availability.
Researcher notes
The evidence is concise and incomplete. The Chromium issue may not provide public technical detail, and the cited Chrome release URL appears desktop-oriented while the CVE description names Android. Avoid expanding affected scope beyond Chrome on Android without vendor confirmation.
Mitigation direction
Update Chrome on Android to 148.0.7778.216 or later where available.
Check Google Chrome release guidance for channel-specific Android update availability.
Prioritize managed Android devices used by executives and privileged staff.
Enforce mobile browser update compliance through MDM where available.
Restrict use of outdated Chrome versions until patched.
Validation and detection
Inventory Android Chrome versions across managed devices.
Confirm no devices run Chrome earlier than 148.0.7778.216.
Review MDM compliance reports for browser update failures.
Check whether Google has published additional Android-specific guidance.
Track CISA KEV and vendor references for exploitation updates.
Based on public source material and reviewed before publication.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-416: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve
time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present,
the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-416 · source CWE mapping
Use After Free
Use After Free represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.