Junglewise Threat Intelligence

CVE-2026-14428: Google Chrome improper input validation in Dawn

CVE-2026-14428 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is affected by a security vulnerability in its Dawn graphics component. A remote attacker who has already compromised the browser's rendering process could use a specially crafted web page to bypass security boundaries (sandbox escape). This could allow the attacker to gain broader access to the underlying mobile device beyond the restricted browser environment.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within Dawn, the WebGPU implementation in Chromium. The flaw exists in Google Chrome for Android versions prior to 150.0.7871.46. An attacker who has already achieved code execution within the sandboxed renderer process can exploit this insufficient validation to perform a sandbox escape. The attack vector involves enticing a user to visit a malicious website or load a crafted HTML page. Successful exploitation allows the attacker to break out of the browser's security isolation and potentially execute commands with the privileges of the browser application on the Android operating system.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Stable channel update released for desktop/Android versions.
  • 2026-07-01: advisory: NVD and Chromium advisory published.

References

Related threats