CVE-2026-17741

Google · Chrome

A sandbox escape vulnerability in Google Chrome for Android exists due to insufficient validation of untrusted input in WebView, which could allow a remote attacker to compromise the browser sandbox.

Executive summary

A critical sandbox escape vulnerability in Google Chrome for Android could allow a remote attacker to bypass security boundaries via a specially crafted HTML page.

Vulnerability

This vulnerability involves insufficient validation of untrusted input within the WebView component, enabling a remote, unauthenticated attacker to escape the browser sandbox through a malicious web page. Successful exploitation requires user interaction to navigate to the crafted content.

Business impact

A successful exploit allows an attacker to break out of the browser sandbox, potentially leading to unauthorized access to device data or execution of arbitrary code within the context of the application. Given the CVSS score of 7.1, this vulnerability poses a significant risk to organizational mobility and endpoint security, as sandbox escapes are often precursors to broader device compromise.

Remediation

Immediate Action: Update the Google Chrome application on all affected Android devices to version 151.0.7922.72 or later immediately.

Proactive Monitoring: Review mobile device management (MDM) logs for unusual application behavior and monitor network traffic for connections to suspicious domains that might host exploit content.

Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to assist in the detection of potentially harmful applications or content that may attempt to leverage such vulnerabilities.

Exploitation status

Public Exploit Available: No (no confirmed public exploit exists in the provided data).

Analyst recommendation

The severity of this vulnerability is elevated due to its potential to break core browser security boundaries. Security teams should prioritize the deployment of the 151.0.7922.72 update across all managed Android assets. Prompt remediation is essential to prevent potential sandbox escape attempts that could lead to further device compromise.