CVE-2026-7905
8.3Google · Chrome on Android
Insufficient input validation in Media in Google Chrome on Android allows potential sandbox escape via crafted HTML.
Executive summary
An input validation vulnerability in Google Chrome on Android allows remote attackers to potentially achieve a sandbox escape through a crafted HTML page.
Vulnerability
This issue involves insufficient validation of untrusted input within the Media component, classified under CWE-20, requiring an unauthenticated attacker to leverage a compromised renderer process and user interaction via a crafted HTML page.
Business impact
A successful exploitation of this vulnerability could lead to total compromise of the underlying system security boundary, resulting in severe data loss, unauthorized access, and complete system compromise. With a CVSS score of 8.3, this high severity vulnerability poses significant risks to mobile device integrity and organizational data security.
Remediation
Immediate Action: Update Google Chrome on Android to version 148.0.7778.96 or later.
Proactive Monitoring: Monitor mobile device fleet compliance and review browser update adoption rates across enterprise endpoints.
Compensating Controls: Ensure standard user interaction controls and browsing security policies are enforced on all managed mobile devices.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the high CVSS score of 8.3 and the potential for complete security boundary bypass, security teams must treat this vulnerability with high priority. Organizations should immediately push updates for Google Chrome on Android to all managed endpoints to mitigate the risk of remote sandbox escape.