Junglewise Threat Intelligence

CVE-2026-17681: Google Chrome Web Authentication sandbox escape on Android

CVE-2026-17681 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android contains a security vulnerability in its Web Authentication component, which handles secure logins. A remote attacker who has already compromised the browser's content-rendering process could use a specially crafted webpage to bypass security boundaries (sandbox escape). This could allow the attacker to gain broader access to the underlying Android operating system and user data beyond what a web browser should normally be able to reach.

Technical details

A vulnerability classified as improper input validation (CWE-20) exists in the Web Authentication component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input, which can be leveraged by a remote attacker. A precondition for this exploit is a prior compromise of the renderer process. By directing a user to a crafted HTML page, the attacker can potentially achieve a sandbox escape, moving from the restricted renderer environment to the browser process or the underlying operating system. This issue was addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-05-26: disclosed: Reported to Chromium project
  • 2026-07-29: patched: Fixed in stable channel update 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats