Executive brief
Google Chrome on Android is a mobile web browser used for accessing the internet. A security vulnerability in the browser's graphics processing component could allow a malicious website to break out of the browser's security 'sandbox.' If successful, an attacker who has already gained limited control over a browser tab could gain broader access to the underlying Android device, potentially leading to data theft or unauthorized system access.
Technical details
An improper input validation vulnerability exists in the GPU component of Google Chrome on Android. The flaw allows a remote attacker who has already compromised the renderer process (for example, via a separate memory corruption bug) to bypass sandbox restrictions. By tricking a user into visiting a specially crafted HTML page, the attacker can leverage insufficient validation of untrusted input to escape the process isolation and execute code with elevated privileges on the host operating system. This issue was addressed in Chrome version 148.0.7778.216.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop and Android versions.
- 2026-05-28: disclosed: CVE published to NVD.