Executive brief
A security vulnerability exists in Google Chrome for Android that could allow a malicious website to bypass the browser's security sandbox. The sandbox is a critical defense layer designed to prevent malicious code from interacting with the rest of the device or accessing private data. If exploited, an attacker who has already gained control over a website's rendering process could potentially gain broader access to the underlying Android operating system.
Technical details
An improper input validation vulnerability (CWE-20) exists in the GPU component of Google Chrome for Android. The flaw allows a remote attacker who has already compromised the renderer process to escalate privileges and escape the browser sandbox by providing specially crafted input. This attack is typically delivered via a malicious HTML page. The vulnerability was addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-04-07: disclosed: Reported to Chrome by Google researchers
- 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date