Executive brief
Google Chrome on Android contains a critical security vulnerability in Dawn, a component used for processing web graphics. A remote attacker can exploit this flaw by tricking a user into visiting a specially crafted website. Successful exploitation could allow the attacker to break out of the browser's security sandbox, potentially gaining unauthorized access to the underlying mobile operating system and user data.
Technical details
A critical vulnerability exists in the Dawn component of Google Chrome for Android due to improper input validation (CWE-20). The flaw is triggered when the browser processes untrusted input from a malicious web page. A remote, unauthenticated attacker can exploit this by hosting a crafted HTML page that, when visited, allows for a sandbox escape. This bypasses the primary security boundary of the browser, potentially leading to remote code execution with the privileges of the browser process or higher. Google has addressed this issue in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-28: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory