Executive brief
A security vulnerability has been identified in Google Chrome for Android's speech component. This flaw could allow a remote attacker who has already partially compromised the browser's internal processing to gain higher levels of authority on the device. This could potentially lead to unauthorized access to sensitive user data or system functions beyond the browser's normal restrictions.
Technical details
An insufficient policy enforcement vulnerability exists in the Speech component of Google Chrome for Android prior to version 151.0.7922.72. The flaw allows a remote attacker who has already compromised the renderer process to escalate privileges by enticing a user to visit a specially crafted HTML page. This bypasses security boundaries intended to isolate the renderer from more sensitive browser processes. The issue is addressed in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for Android/Desktop
- 2026-07-30: disclosed: NVD publication date