Executive brief
A security vulnerability exists in the Google Chrome browser for Android that could allow a malicious website to bypass security protections. If a user visits a specially crafted webpage, an attacker who has already gained limited control over the browser's rendering process could escape the 'sandbox'—a security layer designed to keep web content isolated from the rest of the device. This could potentially allow the attacker to access sensitive data or perform unauthorized actions on the mobile device.
Technical details
A vulnerability classified as an 'Inappropriate Implementation' (CWE-20) exists in the GPU component of Google Chrome on Android. The flaw allows a remote attacker to achieve a sandbox escape if they have already compromised the renderer process. The attack is triggered when a user navigates to a maliciously crafted HTML page. By exploiting this implementation error, the attacker can break out of the process isolation (sandbox) to interact with more sensitive parts of the system. The issue is resolved in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Stable channel update released for desktop and mobile.
- 2026-06-04: disclosed: NVD publication date.