Executive brief
A security vulnerability exists in Google Chrome for Android's speech recognition component. An attacker who has already partially compromised the browser's internal processes could use a specially crafted website to gain higher-level permissions on the device. This could allow the attacker to bypass security boundaries and potentially access sensitive user data or system functions.
Technical details
This vulnerability is classified as an improper input validation (CWE-20) issue within the Speech component of Google Chrome for Android. The flaw exists in versions prior to 150.0.7871.47. An attacker who has already achieved code execution within a sandboxed renderer process can exploit this lack of validation to escalate privileges. The attack is triggered when a user visits a malicious HTML page. Successful exploitation allows the attacker to break out of the renderer sandbox or gain unauthorized access to browser-level functions. Google has addressed this in the stable channel update 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched