Executive brief
A security vulnerability exists in the Google Chrome browser for Android that could allow a malicious website to bypass security restrictions. By tricking a user into interacting with a specially crafted web page, an attacker who has already partially compromised the browser's internal processes could escape the 'sandbox'—a security layer designed to keep web content isolated from the rest of the device. This could lead to unauthorized access to device data or further system compromise.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Drag and Drop component of Google Chrome for Android. The flaw allows a remote attacker who has already achieved code execution within the renderer process to perform a sandbox escape. By leveraging a crafted HTML page, the attacker can bypass the process isolation boundaries. This vulnerability was addressed in version 149.0.7827.53. The exploit requires the attacker to have a foothold in the renderer process and typically involves user interaction with a malicious web page.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 stable channel update released
- 2026-06-04: disclosed: CVE published to NVD