CVE-2026-79132

Google · Chrome

A remote attacker who has compromised the renderer process in Google Chrome for Android can exploit improper input validation to execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

Google Chrome for Android is vulnerable to a remote code execution flaw that allows attackers to escape the browser sandbox, posing a severe risk to device integrity.

Vulnerability

This vulnerability involves improper input validation within the browser input handling mechanism. An unauthenticated remote attacker can leverage this flaw to escape the security sandbox after compromising the renderer process.

Business impact

The ability to execute arbitrary code outside the browser sandbox represents a critical security failure, as it allows attackers to bypass the primary defensive boundary of the application. Given the CVSS score of 8.3, this high-severity vulnerability could lead to full device compromise, unauthorized access to sensitive user data, and potential lateral movement within the mobile environment.

Remediation

Immediate Action: Update Google Chrome on all Android devices to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Monitor device application logs for unusual crash patterns or unexpected process behavior associated with the Chrome browser.

Compensating Controls: Ensure that Google Play Protect is enabled on all enterprise-managed Android devices to detect and block malicious applications that may attempt to exploit browser-based vulnerabilities.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability, combined with the potential for complete sandbox escape, necessitates an urgent response. Administrators should prioritize the deployment of the latest Chrome update across their mobile fleet to ensure the input validation flaw is remediated and the sandbox environment is secured against unauthorized code execution.

More Google CVEs

Sources