Executive brief
A vulnerability exists in Google Chrome for Android within its Bluetooth functionality. This flaw could allow a malicious website to break out of the browser's security sandbox if the attacker has already gained control of the page rendering process. Successfully exploiting this could lead to unauthorized access to the underlying mobile operating system and user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Bluetooth implementation of Google Chrome on Android (CWE-416). The vulnerability is reachable via a crafted HTML page. An attacker who has already achieved remote code execution within the sandboxed renderer process can leverage this memory corruption flaw to escape the sandbox and execute code with higher privileges on the host Android system. The issue is resolved in Google Chrome version 151.0.7922.72 and later.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date