Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A security vulnerability in the browser's accessibility features could allow a malicious website to bypass the browser's security protections (the sandbox). If exploited, this could allow an attacker to gain unauthorized access to the underlying Android operating system and user data.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Accessibility component of Google Chrome for Android. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can leverage the insufficient validation to break out of the restricted browser environment and execute commands with the privileges of the Chrome application on the Android OS. This vulnerability was addressed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-06-06: disclosed: Reported by Google internal researchers
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: advisory: NVD publication date