CVE-2026-95281
Buffer overflow in ANGLE in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Published Sep 29, 2026
- CVSS 9.6 critical
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available
Affected software
In the news
- ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats The Hacker News ·
- Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution CIS MS-ISAC ·
- Update Chrome: 108 security fixes for desktop, new release for Android Malwarebytes Labs ·
- Multiple vulnerabilities in Google Chrome CERT-FR ·