CVE-2026-19143
Google · Chrome
Google Chrome on Android contains an input validation vulnerability in WebAPKs that may allow for unintended execution or data handling.
Executive summary
A critical input validation vulnerability exists in the WebAPK component of Google Chrome on Android, potentially allowing for security boundary bypasses.
Vulnerability
This vulnerability involves insufficient validation of untrusted input within WebAPKs. It requires user interaction and is exploitable locally, potentially leading to a compromise of the application sandbox.
Business impact
While the attack vector is local, the high CVSS score of 8.6 reflects the potential for total technical impact, including data compromise and unauthorized code execution. This could lead to the theft of sensitive mobile data or the installation of malicious applications on user devices.
Remediation
Immediate Action: Update Google Chrome on Android to the latest available version provided by the Google Play Store.
Proactive Monitoring: Monitor mobile device management (MDM) consoles for devices running outdated versions of the Chrome browser.
Compensating Controls: Enforce organizational policies requiring mandatory application updates for all managed mobile devices.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Organizations should ensure that all Android devices in their fleet are updated to the latest version of Chrome. Given the potential for total technical impact, timely patching is essential to maintain the integrity of mobile application environments.