Google Chrome & Android Zero-Days and Security Updates — June 2026
Originally reported viaGoogle Project Zero Vulnerability Research · Google Chrome Stable Channel Update · Android Security Bulletin June 2026Google shipped emergency patches for Chrome on 6 June 2026 addressing two zero-day vulnerabilities — CVE-2026-2783 (Type Confusion in V8, CVSS 8.8) and CVE-2026-2801 (Use-After-Free in WebAudio, CVSS 8.1) — both confirmed as exploited in the wild. The June Android Security Bulletin, released 2 June 2026, addresses CVE-2026-0847 (Kernel Privilege Escalation, CVSS 7.8), described by Google Project Zero as exploited in targeted commercial spyware campaigns.
Chrome V8 and WebAudio zero-days: exploitation pattern
CVE-2026-2783 (V8 Type Confusion) is a renderer-process vulnerability exploitable via a crafted webpage — no user action beyond visiting the page is required if paired with a sandbox escape. The exploitation chain documented by Google's Threat Analysis Group involved a compromised advertising network delivering the exploit via a malicious iframe, affecting users of Chrome versions prior to 126.0.6478.114. CVE-2026-2801 (WebAudio Use-After-Free) requires user interaction (playing crafted audio content) but has been observed in drive-by delivery via malicious media embeds.
Android kernel privilege escalation in surveillance campaigns
CVE-2026-0847 affects the Linux kernel component of Android and allows a local application with no special permissions to escalate to root. Google Project Zero attributed exploitation to a commercial surveillance vendor targeting journalists and civil society members in three countries. The vulnerability affects Android 12, 13, and 14 on devices that had not applied the June 2026 security patch level.
- Force a Chrome browser restart across all managed endpoints within 24 hours to apply the 126.0.6478.114 patch.
- Verify Chrome version via your endpoint management platform — auto-update does not complete until the browser is restarted.
- Use MDM to push the June 2026 Android security patch to all managed devices and set non-compliance as a conditional access block.
- Review network proxy logs for Chrome user-agent strings below version 126.0.6478.114 on internet-facing segments.
- Brief security awareness teams on the malicious ad network delivery vector — standard Safe Browsing protections were bypassed in documented exploitation.
Stay ahead of the threat curve
Get the latest CVE advisories, threat actor intelligence, and detection engineering posts delivered to your inbox.