Executive brief
Google Chrome for Android contains a security vulnerability in its Web Authentication component, which handles secure logins. A remote attacker who has already compromised the browser's content-rendering process could use a specially crafted webpage to bypass security boundaries (sandbox escape). This could allow the attacker to gain broader access to the underlying Android operating system and user data beyond what a web browser should normally be able to reach.
Technical details
A vulnerability classified as improper input validation (CWE-20) exists in the Web Authentication component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input, which can be leveraged by a remote attacker. A precondition for this exploit is a prior compromise of the renderer process. By directing a user to a crafted HTML page, the attacker can potentially achieve a sandbox escape, moving from the restricted renderer environment to the browser process or the underlying operating system. This issue was addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-05-26: disclosed: Reported to Chromium project
- 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
- 2026-07-30: advisory: NVD publication date