Executive brief
A critical vulnerability exists in Google Chrome for Android that could allow an attacker to escape the browser's security sandbox. By tricking a user into visiting a specially crafted website, a remote attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system. This poses a significant risk to device security and the confidentiality of user data.
Technical details
A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the processing of input events. A remote attacker who has already achieved code execution within the renderer process (e.g., via a separate exploit) can leverage this UAF to bypass the Chromium sandbox. Exploitation requires the victim to navigate to a malicious HTML page. Google has addressed this issue in version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-25: disclosed: Reported by Google internal researchers
- 2026-05-12: patched: Fixed in stable channel update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date