


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox…
Published:
30 juli 2026 om 00:00:00
Alert date:
31 juli 2026 om 00:03:35
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17651 is a critical vulnerability in the Dawn graphics component of Google Chrome on Android. The flaw stems from insufficient validation of untrusted input, allowing a remote attacker to potentially escape the browser sandbox. Exploitation is possible via a crafted HTML page, requiring no special privileges beyond getting a user to visit a malicious page. The vulnerability affects Google Chrome versions prior to 151.0.7922.72 on Android. Google has rated this as Critical severity under the Chromium security severity scale. A fix has been issued in the stable channel update. Sandbox escapes of this nature can lead to full device compromise if chained with additional exploits. Users and administrators are advised to update Chrome for Android immediately.
Technical details
Mitigation steps:
Affected products:
Google Chrome on Android (prior to 151.0.7922.72)
Dawn (WebGPU component)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17651
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/517307966
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
