Executive brief
A critical security vulnerability has been identified in Google Chrome for Android's graphics engine, Skia. This flaw could allow a malicious website to break out of the browser's security sandbox, which is the primary layer of defense that keeps web content isolated from the rest of the device. If exploited, an attacker could gain unauthorized access to the underlying Android operating system, potentially leading to the theft of sensitive data or full device compromise.
Technical details
A sandbox escape vulnerability exists in the Skia graphics component of Google Chrome for Android. The flaw is categorized as an 'inappropriate implementation' that can be triggered via a specially crafted HTML page. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this vulnerability to bypass the sandbox boundary and execute arbitrary code with the privileges of the browser process or the underlying operating system. This is a multi-stage attack requiring an initial renderer compromise. Google has addressed this in version 148.0.7778.216.
Affected products
- Google Chrome for Android prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Fixed in Chrome for Android version 148.0.7778.216
- 2026-05-28: disclosed: CVE published by NVD