External risk intelligence

Google Chrome for Android Buffer Overflow Allows Code Execution Outside Sandbox

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-95283

The vulnerability exists within the Google Chrome browser on Android. Browser vulnerabilities are client-side issues that require a user to visit a malicious or compromised web page, rather than representing an internet-facing service, appliance, or infrastructure component that is public-facing by design.

Buffer Overflow

Google Chrome

before 154.0.8037.57

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A buffer overflow vulnerability has been identified in the Tint component within Google Chrome on Android devices. This flaw could allow a remote attacker to execute unauthorized code by tricking a user into visiting a specially crafted webpage. While the severity is high, the primary concern for leadership is to confirm if this specific technology is in use within the organization and assess potential exposure.

  • Code execution flaw in browser technology.
  • Requires user interaction to exploit.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could trick a user into visiting a malicious webpage, which then triggers a buffer overflow vulnerability within the Chrome browser on Android. This vulnerability, if exploited, could allow the attacker to execute arbitrary code on the user's device, bypassing security sandboxing.

  • Requires a user to visit a malicious page.
  • Triggered by a crafted HTML page.
  • Potential for arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A buffer overflow vulnerability in Chrome on Android could allow a remote attacker to execute arbitrary code outside the sandbox by convincing a user to visit a crafted HTML page. This could affect the confidentiality, integrity, and availability of the user's device when browsing the web.

  • Device code execution
  • User visits malicious page
  • Compromise of device data and functions

Operational Fix

Recommended remediation, mitigation, and detection steps

The real-world ownership for this buffer overflow vulnerability in Google Chrome on Android typically falls to platform or mobile application teams responsible for managing the browser on end-user devices. The immediate first step is to identify all Android devices using the affected Chrome version, confirm their business criticality, and then engage with the appropriate device owners or endpoint management teams to plan remediation, coordinating with Google for potential updates.

  • Platform and mobile application teams own the issue.
  • Verify affected Chrome versions and device reachability.
  • Plan remediation with device owners and Google.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Tint component in Google Chrome for Android?

Tint is a functional module within the Google Chrome browser engine on Android devices. It handles specific rendering or visual processing tasks. Because Chrome is the primary interface for web navigation on these mobile devices, vulnerabilities in internal components like Tint can impact the browser's overall security architecture and its ability to safely process web content.

What does CWE-122 mean for CVE-2026-95283?

CWE-122 refers to a heap-based buffer overflow. In plain terms, the software accidentally writes more data to a temporary memory storage area, or buffer, than it is designed to hold. This overflow can overwrite adjacent memory, which a remote attacker might manipulate to force the browser to run unauthorized instructions, essentially breaking out of the security protections intended to isolate web pages.

How is this Chrome vulnerability triggered?

An attacker triggers this flaw by luring a user to visit a specially crafted HTML page designed to exploit the memory overflow. It does not trigger simply by having the browser installed or running in the background. The bug requires active navigation to the malicious content to initiate the overflow, meaning standard browser usage of reputable sites does not cause this issue.

Is my organization at risk from this CVE?

According to Halo Surface Signal, this is considered a client-side issue rather than an internet-facing infrastructure vulnerability. Because it requires a user to interact with a specific malicious page, the risk depends on your employees' browsing habits on Android devices rather than public-facing services. Assessing the number of Android devices in your environment using older Chrome versions is the best way to determine your footprint.

What should I do to fix this browser issue?

The primary response is to update the Chrome browser on all Android devices to version 154.0.8037.57 or higher. Since mobile application or platform teams usually manage these updates, you should coordinate with them to verify which devices are running outdated versions and ensure the latest patch from Google is deployed across your mobile fleet.

References