Description
Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in the Chrome user interface on Android allows a local attacker to craft a malicious file that, when opened by Chrome, escalates the attacker’s privileges on the device. This input-validation weakness (CWE-20) permits malformed UI data to be processed without adequate checks, enabling Chrome to perform actions with elevated privileges.

Affected Systems

Google Chrome for Android, versions prior to 150.0.7871.47. Users running any of those builds are exposed, as the flaw is confined to the UI component that processes file inputs.

Risk and Exploitability

The vulnerability has a CVSS score of 7.8, indicating high severity, while its EPSS score of <1% is unlikely at present. It is not listed in the CISA KEV catalog. The likely attack vector is local; a local attacker who can drop a crafted file onto the device and cause Chrome’s UI to process that file can trigger the attack, which requires only local access and does not rely on remote execution.

Generated by OpenCVE AI on July 17, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (150.0.7871.47 or later) to fix the input-validation flaw (CWE-20).
  • Restrict Chrome's file access in Android settings to block unknown sources and limit the attack surface for the CWE-20 vulnerability.
  • Avoid opening unknown or suspicious files with Chrome, and consider removing or disabling file handling for untrusted apps if possible.

Generated by OpenCVE AI on July 17, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Android UI Enables Local Privilege Escalation

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Malformed File Input in Chrome for Android

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Malformed File Input in Chrome for Android

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Malicious File in Chrome on Android UI

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Malicious File in Chrome on Android UI

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Android Chrome UI Input Validation Flaw Enables Local Privilege Escalation

Thu, 09 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Android Chrome UI Input Validation Flaw Enables Local Privilege Escalation

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Untrusted Input in Chrome Android UI

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Untrusted Input in Chrome Android UI

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Android: Local Privilege Escalation via Malformed UI File Input

Mon, 06 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Chrome Android: Local Privilege Escalation via Malformed UI File Input

Sun, 05 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome Android UI Enables Local Privilege Escalation

Sun, 05 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome Android UI Enables Local Privilege Escalation

Sat, 04 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Untrusted UI Input in Android Chrome

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Untrusted UI Input in Android Chrome

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Malformed UI File on Chrome for Android

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Malformed UI File on Chrome for Android

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome UI Allows Local Privilege Escalation

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome UI Allows Local Privilege Escalation

Thu, 02 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chrome Android Privilege Escalation via Malicious File

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Android Privilege Escalation via Malicious File

Wed, 01 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted UI Input in Google Chrome on Android Enables Local Privilege Escalation

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted UI Input in Google Chrome on Android Enables Local Privilege Escalation

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome on Android Privilege Escalation via Malicious File

Wed, 01 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome on Android Privilege Escalation via Malicious File

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:00.615Z

Reserved: 2026-06-29T23:03:54.111Z

Link: CVE-2026-13927

cve-icon Vulnrichment

Updated: 2026-07-01T14:09:44.228Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation