DIRAS TAKE
Urgent: patch immediately — public exploit code exists and the issue is fixed in Chrome 151.0.7922.169. Prioritize updating Android Chrome clients that remain on the 151.x branch and restrict exposure until patched.
What is CVE-2026-76036?
Remote attackers can execute arbitrary code in Google Chrome on Android by convincing a user to load a malicious page; this is tracked as CVE-2026-76036. The flaw is a buffer overflow in the Dawn component and affects Chrome 151.0.7922.169 and earlier on the 151.x branch; an attacker needs a crafted HTML page and user interaction (a visit/click) to trigger it. The weakness is classified as CWE-122 (Heap-based Buffer Overflow).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 151.x | 151.0.7922.169 – before 151.0.7922.169 | 151.0.7922.169 |
Is CVE-2026-76036 being exploited?
Public exploit code is available.
How to fix CVE-2026-76036
- Update Chrome on affected Android devices to 151.0.7922.169.
- If immediate update is impossible, restrict access to untrusted web content and block risky page rendering where feasible.
- Monitor browser crash and security logs for suspicious renderer crashes or unexpected process terminations.
- Apply vendor guidance and run endpoint detection for indicators of compromise related to crafted HTML payloads.
Frequently asked questions
Is CVE-2026-76036 being actively exploited?
Public exploit code is available for CVE-2026-76036, indicating a heightened risk of active exploitation.
Which Chrome versions are affected by CVE-2026-76036?
Chrome on Android in the 151.x branch is affected; specifically versions before 151.0.7922.169 are vulnerable.
Is there a patch for CVE-2026-76036?
Yes. Google fixed the vulnerability in Chrome version 151.0.7922.169 on the 151.x branch.
Does CVE-2026-76036 require authentication?
No authentication is required; an attacker only needs to get a user to load a crafted HTML page in the vulnerable Chrome on Android.
References
- nvd.nist.gov/vuln/detail/CVE-2026-76036
- cve.org/CVERecord?id=CVE-2026-76036
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0826575033.html
- issues.chromium.org/issues/540087398
- All Google CVEs on CVE Radar
- CVEs published in September 2026