CVE-2026-79132
Google · Chrome
A remote attacker who has compromised the renderer process in Google Chrome for Android can exploit improper input validation to execute arbitrary code outside the sandbox via a crafted HTML page.
Executive summary
Google Chrome for Android is vulnerable to a remote code execution flaw that allows attackers to escape the browser sandbox, posing a severe risk to device integrity.
Vulnerability
This vulnerability involves improper input validation within the browser input handling mechanism. An unauthenticated remote attacker can leverage this flaw to escape the security sandbox after compromising the renderer process.
Business impact
The ability to execute arbitrary code outside the browser sandbox represents a critical security failure, as it allows attackers to bypass the primary defensive boundary of the application. Given the CVSS score of 8.3, this high-severity vulnerability could lead to full device compromise, unauthorized access to sensitive user data, and potential lateral movement within the mobile environment.
Remediation
Immediate Action: Update Google Chrome on all Android devices to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor device application logs for unusual crash patterns or unexpected process behavior associated with the Chrome browser.
Compensating Controls: Ensure that Google Play Protect is enabled on all enterprise-managed Android devices to detect and block malicious applications that may attempt to exploit browser-based vulnerabilities.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The severity of this vulnerability, combined with the potential for complete sandbox escape, necessitates an urgent response. Administrators should prioritize the deployment of the latest Chrome update across their mobile fleet to ensure the input validation flaw is remediated and the sandbox environment is secured against unauthorized code execution.