top of page
perceptive_background_267k.jpg

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromise…

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 19:11:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17681 is a high-severity vulnerability in Google Chrome for Android affecting versions prior to 151.0.7922.72. The flaw resides in the Web Authentication component, where insufficient validation of untrusted input allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox. Exploitation requires a crafted HTML page to trigger the vulnerability. The attack vector is remote, and the issue has been rated High by Chromium's internal security severity scale. Google has addressed the issue in Chrome 151.0.7922.72 for Android. The vulnerability is currently awaiting full analysis on the NVD. Users are advised to update their Chrome browser on Android immediately to mitigate the risk of sandbox escape attacks.

Technical details

Mitigation steps:

Affected products:

Google Chrome for Android prior to 151.0.7922.72

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page