


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromise…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 17:11:53
Source:
nvd.nist.gov
Mobile & IoT, Web Technologies, Zero-Day Vulnerabilities
CVE-2026-17681 is a high-severity vulnerability in Google Chrome for Android affecting versions prior to 151.0.7922.72. The flaw resides in the Web Authentication component, where insufficient validation of untrusted input allows a remote attacker who has already compromised the renderer process to potentially escape the sandbox. Exploitation requires a crafted HTML page to trigger the vulnerability. The attack vector is remote, and the issue has been rated High by Chromium's internal security severity scale. Google has addressed the issue in Chrome 151.0.7922.72 for Android. The vulnerability is currently awaiting full analysis on the NVD. Users are advised to update their Chrome browser on Android immediately to mitigate the risk of sandbox escape attacks.
Technical details
Mitigation steps:
Affected products:
Google Chrome for Android prior to 151.0.7922.72
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17681
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/516813184
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
