Executive brief
A security vulnerability exists in Google Chrome for Android that could allow a malicious file to bypass the browser's security sandbox. The sandbox is a critical layer of defense designed to keep web-based threats from accessing the rest of the mobile device. If exploited, an attacker could potentially gain unauthorized access to system resources or perform actions outside the restricted browser environment.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebAppInstalls component of Google Chrome for Android. By providing a specially crafted malicious file, a local attacker can bypass the browser's sandbox restrictions. This sandbox escape could allow an attacker to execute code or access data outside of the intended process boundaries. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched