CVE-2026-6920General(google / android)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome
  • linux_kernel
  • windows

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-04-24); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Products
androidchromelinux_kernelwindows

1 version affected across 4 products

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-04-24: 2Mentions · 2026-04-26: 1Mentions · 2026-04-30: 2Mentions · 2026-05-05: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-05: 104-2404-2604-3005-0505-13
Signal classification3 categories
General
342.9%
Disclosure
228.6%
Patch
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-242
Disclosure1General1
2026-04-261
General1
2026-04-302
Disclosure1Patch1
2026-05-051
Patch1
2026-05-131
General1
Full discourse7 posts
  • Wazuh@wazuh
    Patch

    Google Chrome (Android) is affected by CVE-2026-6920 (CVSS 9.6; Chromium severity: High), an out-of-bounds read in the GPU that may enable sandbox escape. The issue is fixed in version 147.0.7727.117. Read more: https://ow.ly/tB6350YUXff https://t.co/mDFgBMhVuF

    Post summary

    Google Chrome for Android is impacted by CVE‑2026‑6920, a high‑severity out‑of‑bounds read that could allow sandbox escape; the vulnerability is fixed in version 147.0.7727.117.

    070132480
    8.1K followersView on X
  • S2GRUPO@s2grupo
    Patch

    Vulnerabilidades CVE-2026-6919 y CVE-2026-6920 afectan a componentes internos del motor del navegador Google Chrome. Se recomienda actualizar a la versión 147.0.7727.117 o superior. https://hubs.la/Q04dK0bR0

    Post summary

    Advisory warns that CVE‑2026‑6919 and CVE‑2026‑6920 affect Chrome’s internal engine components and urges users to update to v147.0.7727.117 or newer.

    00031259
    5.1K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【アーカイブ】 【脆弱性情報】 CVE-2026-6920 googleのchromeの脆弱性について https://www.cybernote.click/2026/04/27/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-6920-google%e3%81%aechrome%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/?utm_source=rss&utm_medium=rss&utm_campaign=%25e3%2580%2590%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e6%2583%2585%25e5%25a0%25b1%25e3%2580%2591-cve-2026-6920-google%25e3%2581%25aechrome%25e3%2581%25ae%25e8%2584%2586%25e5%25bc%25b1%25e6%2580%25a7%25e3%2581%25ab%25e3%2581%25a4%25e3%2581%2584%25e3%2581%25a6 #ブログ仲間と繋がりたい #Webライター

    Post summary

    The post references a blog link about CVE-2026-6920 but offers no technical, exploit, or patch details, thus serving as a general mention of the vulnerability.

    0001069
    211 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6920 Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6920

    Post summary

    The post announces CVE-2026-6920 as an out‑of‑bounds read vulnerability in Chrome for Android that could enable sandbox escape, with no mention of exploitation, patches, or PoC details.

    1000082
    4.0K followersView on X
  • Aakash Rahsi@rahsi_aaka
    Disclosure

    CVE-2026-6920 | Chromium: CVE-2026-6920 Out of bounds read in GPU | Rahsi Framework™ https://www.aakashrahsi.online/post/cve-2026-6920 https://t.co/5VZBrkGtW9

    Post summary

    The post announces CVE‑2026‑6920, an out‑of‑bounds read in Chromium’s GPU, but offers no exploitation, mitigation, or PoC details.

    0000016
    1 followersView on X
  • たるいひでと@TaruiHideto
    General

    CVE-2026-6920 は Edge に関係ないようですね(とりあえず、今のところ修正リストには載ってない

    Post summary

    The post indicates that CVE-2026-6920 does not appear to affect Edge and is not listed on the current fix list, with no further technical or actionable details provided.

    0000098
    540 followersView on X
  • haeretics@略称ヘレ@haeretics
    General

    CVE番号が付番されたのは以下の3件 CVE-2026-6919:High(深刻度) CVE-2026-6920:High CVE-2026-6921:Medium

    Post summary

    Three new CVEs (CVE-2026-6919, CVE-2026-6920, CVE-2026-6921) are announced with their severity ratings, but no further technical or exploitation details are provided.

    0000067
    472 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more