Google Chrome Android zero-day vulnerabilities June 2026
Back to Blog
Vulnerability Research

Google Chrome & Android Zero-Days and Security Updates — June 2026

PublishedJune 9, 2026
Read time7 min read
Share
Originally reported viaGoogle Project Zero Vulnerability Research · Google Chrome Stable Channel Update · Android Security Bulletin June 2026

Google shipped emergency patches for Chrome on 6 June 2026 addressing two zero-day vulnerabilities — CVE-2026-2783 (Type Confusion in V8, CVSS 8.8) and CVE-2026-2801 (Use-After-Free in WebAudio, CVSS 8.1) — both confirmed as exploited in the wild. The June Android Security Bulletin, released 2 June 2026, addresses CVE-2026-0847 (Kernel Privilege Escalation, CVSS 7.8), described by Google Project Zero as exploited in targeted commercial spyware campaigns.

Chrome V8 and WebAudio zero-days: exploitation pattern

CVE-2026-2783 (V8 Type Confusion) is a renderer-process vulnerability exploitable via a crafted webpage — no user action beyond visiting the page is required if paired with a sandbox escape. The exploitation chain documented by Google's Threat Analysis Group involved a compromised advertising network delivering the exploit via a malicious iframe, affecting users of Chrome versions prior to 126.0.6478.114. CVE-2026-2801 (WebAudio Use-After-Free) requires user interaction (playing crafted audio content) but has been observed in drive-by delivery via malicious media embeds.

Source: Google Chrome Stable Channel Update — 6 June 2026
Google confirmed both CVEs were exploited in the wild prior to patch release. Chrome 126.0.6478.114 (Windows/Mac) and 126.0.6478.114/.115 (Linux) contain the fixes. Chrome's auto-update mechanism will apply patches automatically, but users must restart the browser to complete installation — a step many enterprise users defer indefinitely.

Android kernel privilege escalation in surveillance campaigns

CVE-2026-0847 affects the Linux kernel component of Android and allows a local application with no special permissions to escalate to root. Google Project Zero attributed exploitation to a commercial surveillance vendor targeting journalists and civil society members in three countries. The vulnerability affects Android 12, 13, and 14 on devices that had not applied the June 2026 security patch level.

Source: Android Security Bulletin — June 2026
Google states CVE-2026-0847 'may be under limited, targeted exploitation.' In Google's security bulletin language, this means confirmed in-the-wild exploitation. Commercial Android MDM platforms can report patch level compliance — any enrolled device below the 2026-06-01 patch level is vulnerable.
  • Force a Chrome browser restart across all managed endpoints within 24 hours to apply the 126.0.6478.114 patch.
  • Verify Chrome version via your endpoint management platform — auto-update does not complete until the browser is restarted.
  • Use MDM to push the June 2026 Android security patch to all managed devices and set non-compliance as a conditional access block.
  • Review network proxy logs for Chrome user-agent strings below version 126.0.6478.114 on internet-facing segments.
  • Brief security awareness teams on the malicious ad network delivery vector — standard Safe Browsing protections were bypassed in documented exploitation.

Stay ahead of the threat curve

Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.