CVE-2026-17651
Google · Chrome
Insufficient validation of untrusted input in the Dawn component of Google Chrome on Android allows a remote attacker to perform a sandbox escape via a crafted HTML page.
Executive summary
A critical input validation vulnerability in Google Chrome on Android allows remote attackers to bypass sandbox protections through crafted web content.
Vulnerability
This is an input validation vulnerability (CWE-20) within the Dawn component. An unauthenticated remote attacker can exploit this via a crafted HTML page to achieve a sandbox escape, requiring user interaction.
Business impact
The CVSS score of 9.6 highlights the critical nature of this flaw. For Android users, a sandbox escape could lead to the compromise of sensitive mobile data, unauthorized access to device hardware, or the installation of malicious applications.
Remediation
Immediate Action: Update Google Chrome for Android to version 151.0.7922.72 or the latest available version through the Google Play Store.
Proactive Monitoring: Use Mobile Device Management (MDM) solutions to ensure that all mobile devices are running updated versions of the Chrome browser.
Compensating Controls: Encourage users to avoid clicking on untrusted links and ensure that the Play Protect feature is enabled on all Android devices.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Mobile devices are frequently overlooked in patch management cycles, yet this vulnerability poses a significant risk to Android environments. Administrators must enforce timely updates across all managed mobile endpoints to mitigate the risk of sandbox escape.