Sceawere

Vulnerability Detail

CVE-2026-76039UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome Android Incorrect Reference Resolution

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
17h ago
Vendor
Google
Product
Chrome
Attack Type
Incorrect reference resolution
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect reference resolution in Core in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-18T21:18:27.947Z",
  "pubdate": "2026-08-18T21:18:27.947Z",
  "executiveSummary": "An incorrect reference resolution vulnerability has been identified within the Core component of Google Chrome on Android prior to version 151.0.7922.169. This security flaw enables a remote threat actor to compromise user data confidentiality through targeted social engineering tactics.\nThe primary impact of successful exploitation is the unauthorized acquisition of sensitive information from the underlying system or browser context. The vulnerability affects Google Chrome on Android operating system environments running software versions preceding 151.0.7922.169.\nRated as a High severity issue by Chromium security standards, the risk implications involve unauthorized data disclosure which could lead to further compromise depending on the sensitive context accessible to the browser instance.\nAttacker capabilities are constrained by the requirement for user interaction, specifically leveraging social engineering techniques to entice the victim into loading a malicious resource. Exploitation requires no prior authentication or elevated privileges within the victim's environment, but relies entirely on the successful rendering of a crafted HTML page within the vulnerable browser context.",
  "technicalDetails": "The root cause of the vulnerability stems from improper reference resolution mechanics within the Core component of Google Chrome on Android. Incorrect reference resolution occurs when software improperly resolves references to internal objects, memory locations, or external resources, potentially leading to unauthorized resource access or memory exposure.\nThe vulnerable component resides within the Core architecture of Google Chrome on Android prior to version 151.0.7922.169. The flaw is exposed to network-based threats via standard web browsing vectors, requiring the target to process web content provided by the attacker.\nThe attack flow begins when a remote attacker deploys a crafted HTML page designed to target the reference resolution flaw. Through social engineering, such as phishing or malicious redirection, the victim is induced to navigate to the attacker-controlled webpage using the vulnerable browser instance.\nUpon rendering the crafted HTML page, the browser processes malicious or malformed resource references that trigger the incorrect reference resolution behavior. Because reference management logic fails to correctly isolate or validate the referenced elements, the browser inadvertently exposes sensitive data associated with internal states or memory structures.\nThe payload behavior involves harvesting the exposed sensitive information and transmitting it back to the remote attacker over standard network protocols. No local authentication or system privileges are required to initiate the attack sequence, as the vulnerability is fully exploitable via remote web content interacting with the unpatched browser engine.\nPost-exploitation impact is characterized by the unauthorized disclosure of sensitive information accessible to the browser session, which may include application data, session tokens, or other confidential user information exposed during the flawed reference resolution process."
}
CVE-2026-76039: Google Chrome Android Incorrect Reference Resolution (MEDIUM Severity, CVSS: 6.5) - Sceawere