
🚨 CRITICAL - Chrome Android Autofill use-after-free sandbox escape (CVE-2026-15113) A use-after-free vulnerability exists in the Autofill component of Google Chrome on Android prior to 150.0.7871.115, triggered during HTML-driven form/autofill handling. The root cause is a use-after-free memory safety flaw where an object is freed and later reused, enabling memory corruption. An attacker can exploit this remotely by luring a user to a crafted HTML page that manipulates Autofill behavior, requiring no special privileges beyond user interaction (page visit). Successful exploitation could allow sandbox escape and potentially lead to arbitrary code execution in a more privileged context, enabling device compromise, data theft, or further exploitation chains. 👉 Affected: Google Chrome for Android < 150.0.7871.115 | Upgrade to 150.0.7871.115
Post summary
Chrome for Android before 150.0.7871.115 has a use‑after‑free flaw in Autofill that could enable sandbox escape via a crafted HTML page; users are advised to upgrade to the fixed version.


