CVE-2026-7905

8.3

Google · Chrome on Android

Insufficient input validation in Media in Google Chrome on Android allows potential sandbox escape via crafted HTML.

Executive summary

An input validation vulnerability in Google Chrome on Android allows remote attackers to potentially achieve a sandbox escape through a crafted HTML page.

Vulnerability

This issue involves insufficient validation of untrusted input within the Media component, classified under CWE-20, requiring an unauthenticated attacker to leverage a compromised renderer process and user interaction via a crafted HTML page.

Business impact

A successful exploitation of this vulnerability could lead to total compromise of the underlying system security boundary, resulting in severe data loss, unauthorized access, and complete system compromise. With a CVSS score of 8.3, this high severity vulnerability poses significant risks to mobile device integrity and organizational data security.

Remediation

Immediate Action: Update Google Chrome on Android to version 148.0.7778.96 or later.

Proactive Monitoring: Monitor mobile device fleet compliance and review browser update adoption rates across enterprise endpoints.

Compensating Controls: Ensure standard user interaction controls and browsing security policies are enforced on all managed mobile devices.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Given the high CVSS score of 8.3 and the potential for complete security boundary bypass, security teams must treat this vulnerability with high priority. Organizations should immediately push updates for Google Chrome on Android to all managed endpoints to mitigate the risk of remote sandbox escape.

More Google CVEs

Sources