CVE-2026-17651

Google · Chrome

Insufficient validation of untrusted input in the Dawn component of Google Chrome on Android allows a remote attacker to perform a sandbox escape via a crafted HTML page.

Executive summary

A critical input validation vulnerability in Google Chrome on Android allows remote attackers to bypass sandbox protections through crafted web content.

Vulnerability

This is an input validation vulnerability (CWE-20) within the Dawn component. An unauthenticated remote attacker can exploit this via a crafted HTML page to achieve a sandbox escape, requiring user interaction.

Business impact

The CVSS score of 9.6 highlights the critical nature of this flaw. For Android users, a sandbox escape could lead to the compromise of sensitive mobile data, unauthorized access to device hardware, or the installation of malicious applications.

Remediation

Immediate Action: Update Google Chrome for Android to version 151.0.7922.72 or the latest available version through the Google Play Store.

Proactive Monitoring: Use Mobile Device Management (MDM) solutions to ensure that all mobile devices are running updated versions of the Chrome browser.

Compensating Controls: Encourage users to avoid clicking on untrusted links and ensure that the Play Protect feature is enabled on all Android devices.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Mobile devices are frequently overlooked in patch management cycles, yet this vulnerability poses a significant risk to Android environments. Administrators must enforce timely updates across all managed mobile endpoints to mitigate the risk of sandbox escape.