


Perceptive Security
SOC/SIEM Consultancy

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer pro…
Published:
29 juli 2026 om 22:00:00
Alert date:
30 juli 2026 om 17:11:53
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
CVE-2026-18002 describes an insufficient input validation vulnerability in Google Lens within Google Chrome versions prior to 151.0.7922.72. A remote attacker who has already compromised the renderer process could potentially escape the browser sandbox by delivering a crafted HTML page. The vulnerability is classified as a sandbox escape, which can allow attackers to break out of Chrome's security isolation mechanisms. Google has rated this with a Chromium security severity of Low, though the broader impact of a successful sandbox escape can be significant. The fix was included in the Chrome stable channel update released in July 2026. The vulnerability is currently undergoing analysis by NVD. No active exploitation has been publicly reported at this time.
Technical details
Mitigation steps:
Affected products:
Google Chrome
Google Lens
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18002
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
https://issues.chromium.org/issues/521864362
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
