


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromise…
Published:
29 July 2026 at 22:00:00
Alert date:
30 July 2026 at 18:03:11
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17681 is a high-severity vulnerability in Google Chrome on Android affecting versions prior to 151.0.7922.72. The flaw stems from insufficient validation of untrusted input in the Web Authentication component. A remote attacker who has already compromised the renderer process could exploit this vulnerability to perform a sandbox escape. The attack vector requires a crafted HTML page to trigger the vulnerability. Google has assigned this a 'High' severity rating under the Chromium security severity scale. A fix has been issued in Chrome stable channel version 151.0.7922.72. Users on Android are advised to update immediately to mitigate the risk of sandbox escapes following renderer compromise.
Technical details
Mitigation steps:
Affected products:
Google Chrome on Android (prior to 151.0.7922.72)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17681
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/516813184
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
