Junglewise Threat Intelligence

CVE-2026-13934: Google Chrome Dawn sandbox escape on Android

CVE-2026-13934 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is a mobile web browser used to access the internet. A security vulnerability in its graphics component could allow a malicious website to bypass the browser's security sandbox. If successful, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying mobile device, potentially compromising user data or device stability.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Dawn component of Google Chrome on Android. Dawn is the implementation of the WebGPU standard in Chromium. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass sandbox restrictions via a specially crafted HTML page. This sandbox escape could lead to further compromise of the host operating system. The issue is resolved in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats