Junglewise Threat Intelligence

CVE-2026-13927: Google Chrome for Android privilege escalation in UI

CVE-2026-13927 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a local attacker to gain elevated privileges on a device. By using a specially crafted malicious file, an attacker could exploit weaknesses in how the browser's user interface handles certain inputs. This could potentially lead to unauthorized access to sensitive data or system functions on the affected mobile device.

Technical details

An improper input validation vulnerability (CWE-20) exists in the UI component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when processing files locally. A local attacker can exploit this vulnerability by tricking the system or user into processing a malicious file, leading to privilege escalation within the context of the application or operating system. The issue is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats