Executive brief
A vulnerability in Google Chrome for Android's Picture-in-Picture feature could allow a malicious website to bypass security protections. If a user visits a specially crafted webpage, an attacker who has already partially compromised the browser's rendering process could escape the restricted 'sandbox' environment. This could lead to broader access to the device's system or data beyond the browser's intended limits.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Picture-in-Picture component of Google Chrome for Android. The flaw allows a remote attacker to perform a sandbox escape if they have already achieved code execution within the renderer process (a 'chained' attack). By enticing a user to visit a malicious HTML page, the attacker can exploit the insufficient validation to break out of the browser's process isolation. This issue was fixed in version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: advisory: NVD publication date