top of page
perceptive_background_267k.jpg

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox…

Published:

30 juli 2026 om 00:00:00

Alert date:

31 juli 2026 om 00:03:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities

CVE-2026-17651 is a critical vulnerability in the Dawn graphics component of Google Chrome on Android. The flaw stems from insufficient validation of untrusted input, allowing a remote attacker to potentially escape the browser sandbox. Exploitation is possible via a crafted HTML page, requiring no special privileges beyond getting a user to visit a malicious page. The vulnerability affects Google Chrome versions prior to 151.0.7922.72 on Android. Google has rated this as Critical severity under the Chromium security severity scale. A fix has been issued in the stable channel update. Sandbox escapes of this nature can lead to full device compromise if chained with additional exploits. Users and administrators are advised to update Chrome for Android immediately.

Technical details

Mitigation steps:

Affected products:

Google Chrome on Android (prior to 151.0.7922.72)
Dawn (WebGPU component)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page