top of page
perceptive_background_267k.jpg

Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromise…

Published:

30 July 2026 at 00:00:00

Alert date:

30 July 2026 at 23:05:50

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17940 is a vulnerability in Google Chrome on Android affecting the Picture-in-Picture feature. The flaw stems from insufficient validation of untrusted input, allowing a remote attacker who has already compromised the renderer process to potentially escape the sandbox. Exploitation requires a crafted HTML page and a pre-compromised renderer, making it a chained attack vector. The vulnerability was patched in Chrome version 151.0.7922.72. Chromium has rated the severity as Low, though sandbox escapes carry inherent risk regardless of base severity. The issue is tracked in the Chromium bug tracker under issue 514069440. Users on Android are advised to update their Chrome browser to the latest stable release.

Technical details

Mitigation steps:

Affected products:

Google Chrome on Android (prior to 151.0.7922.72)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page