Junglewise Threat Intelligence

CVE-2026-10020: Google Chrome Skia improper input validation sandbox escape

CVE-2026-10020 · Severity: info · CVSS 6.5 · Published 2026-05-28

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is affected by a security vulnerability in its graphics engine, Skia. An attacker who has already partially compromised the browser's rendering process could use this flaw to escape the security sandbox. This could allow them to gain broader access to the device's data or functions beyond what a normal web page should be able to reach.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Skia graphics library component of Google Chrome for Android. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within the renderer process (a "chained" attack). By convincing a user to visit a specially crafted HTML page, the attacker can exploit the insufficient validation of untrusted input to bypass security boundaries. This issue is resolved in Chrome version 148.0.7778.216 and later.

Affected products

  • Google Chrome prior to 148.0.7778.216

Timeline

  • 2026-05-27: patched: Stable channel update released
  • 2026-05-28: disclosed: NVD publication date

References

Related threats