Full-chain RCE for Chromium on Android 14–16 for Sale
Dark Web2026-09-28, 10:42
For informational purposes only.
Vulnerability Type: RCE
Vulnerable Versions: Android 14–16
Price: $10k
The author describes the exploit chain developed for Chrome/Chromium WebView on Android 14–16 as “0-day class.”
According to the seller, the chain is as follows:
- Renderer RCE — arbitrary code execution after rendering a malicious web page in Chrome or WebView;
- Sandbox Escape — escaping the Chromium sandbox;
- System Server Pivot — further escalation to the more privileged Android system_server component;
According to the author, installing an APK is reportedly not required, as the exploit uses JavaScript and native shellcode. No additional user interaction is required after the page loads. The exploit is claimed to work via Chrome, WebView, and WebView within third-party apps, including through malicious ad content. The main payload runs entirely in memory, without being permanently pinned by default.
The author claims that the chain has been tested on a Pixel 9/9 Pro running Android 15, a Samsung Galaxy S24 running Android 16 / One UI 8, and a Xiaomi 14 running Android 14 / HyperOS. The package reportedly includes a loader, several stages of shellcode, and a basic C2 component.
Vendors
Products
More