CVE-2026-19157
9.6Google · Chrome
An out of bounds write vulnerability in the ANGLE component of Google Chrome on Android allows remote attackers to execute a sandbox escape via a specially crafted HTML page.
Executive summary
A critical out of bounds write vulnerability in Google Chrome on Android enables remote attackers to achieve a sandbox escape, posing a severe risk to device integrity and user data.
Vulnerability
This is an out of bounds write vulnerability (CWE-787) located in the ANGLE graphics engine component. The vulnerability can be triggered by an unauthenticated remote attacker through a crafted HTML page, requiring user interaction to execute.
Business impact
The ability to perform a sandbox escape allows an attacker to bypass the security boundaries of the browser, potentially leading to unauthorized system access, data theft, or complete device compromise. Given the CVSS score of 9.6, this vulnerability is classified as critical, as it provides a pathway for attackers to escalate privileges beyond the restricted browser environment.
Remediation
Immediate Action: Update Google Chrome to version 151.0.7922.109 or later immediately to incorporate the necessary security patches.
Proactive Monitoring: Monitor device and network security logs for unusual browser activity or unexpected crashes that may indicate exploitation attempts.
Compensating Controls: Ensure that Google Play Protect is enabled on all Android devices to provide an additional layer of defense against malicious applications or content.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the critical severity and the potential for complete sandbox escape, organizations must prioritize the deployment of the latest Chrome update across all Android endpoints. Failure to patch this vulnerability leaves systems exposed to potential remote code execution and unauthorized data access.