Junglewise Threat Intelligence

CVE-2026-17866: Google Chrome for Android type confusion in Tab sandbox escape

CVE-2026-17866 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a remote attacker to bypass security protections that normally isolate web pages from the rest of the device. This issue occurs when the browser incorrectly handles data types within its tab management system. If exploited, an attacker who has already gained control over a website's rendering process could potentially access sensitive information or perform unauthorized actions outside of the browser's restricted environment.

Technical details

A type confusion vulnerability exists in the Tab component of Google Chrome for Android. The flaw stems from the 'Access of Resource Using Incompatible Type' (CWE-843) during tab-related operations. An attacker who has already achieved code execution within a compromised renderer process can leverage this vulnerability via a specially crafted HTML page to perform a sandbox escape. This would allow the attacker to break out of the process isolation and potentially execute code with the privileges of the browser process. The issue is addressed in version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats