Executive brief
A security vulnerability in Google Chrome on Android could allow a malicious website to break out of the browser's security sandbox. This sandbox is designed to keep web content isolated from the rest of the device; if bypassed, an attacker who has already gained some control over the browser process could potentially access sensitive user data or system resources. Users should update to version 148.0.7778.168 or later to mitigate this risk.
Technical details
A vulnerability classified as insufficient policy enforcement exists within the GPU component of Google Chrome for Android. The flaw allows a remote attacker who has already compromised the renderer process to escalate their privileges and perform a sandbox escape by convincing a user to visit a specially crafted HTML page. This bypasses the security boundaries intended to isolate the browser's execution environment from the underlying operating system. The issue is resolved in Google Chrome version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2026-03-10: other: Reported by Mark Blaszczyk
- 2026-05-12: patched: Stable channel update released
- 2026-05-14: disclosed: NVD publication date