Executive brief
Google Chrome for Android contains a security vulnerability in its Sharing component. This flaw could allow a remote attacker to bypass intended navigation restrictions by sending malicious network traffic to the device. While rated as low severity, such a bypass could potentially lead to users being directed to unauthorized or malicious websites.
Technical details
A vulnerability exists in the Sharing component of Google Chrome for Android due to insufficient validation of untrusted input. A remote attacker can exploit this by delivering malicious network traffic, which allows them to bypass navigation restrictions enforced by the browser. This is classified as an input validation flaw. The issue is addressed in version 151.0.7922.72. Access to specific bug details in the Chromium tracker is currently restricted to prevent further exploitation until a majority of users have updated.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed