Description
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input validation flaw in the Text component of Google Chrome for Android allowed a remote attacker who had already compromised the renderer process to supply a crafted HTML page that could escape the sandbox. The flaw is a classic CWE-20 problem where untrusted input is not properly sanitized, leading to potential sandbox escape and arbitrary code execution with elevated privileges on the device. The result is a remote sandbox escape that can compromise the entire system if the renderer has been taken over.

Affected Systems

All installations of Google Chrome for Android before version 150.0.7871.47 are affected, including devices shipped with older Chrome releases or those that have not yet received the latest updates.

Risk and Exploitability

The vulnerability has a CVSS base score of 9.6, indicating high severity, yet an EPSS score of less than 1% and absence from CISA’s KEV catalog suggest it is unlikely to be exploited in the wild. Exploitation requires the attacker to first compromise the renderer process—a significant prerequisite that lowers the likelihood. Nevertheless, if the prerequisites are met, the impact is severe, allowing privilege escalation and broad device compromise.

Generated by OpenCVE AI on August 3, 2026 at 06:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to apply the vendor fix
  • If an immediate update is not possible, use enterprise policy to block loading of untrusted content so that crafted HTML cannot be processed in a compromised renderer
  • Monitor the device for anomalous renderer behavior and ensure only trusted web content is displayed

Generated by OpenCVE AI on August 3, 2026 at 06:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Renderer Process Input Validation Flaw Allows Sandbox Escape via Crafted HTML

Wed, 29 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome Android Renderer Process Input Validation Flaw Allows Sandbox Escape via Crafted HTML

Sat, 25 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Android Text Component Could Enable Sandbox Escape

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Android Text Component Could Enable Sandbox Escape

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Insufficient validation of untrusted input in Chrome Text component allows remote sandbox escape via renderer process

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Insufficient validation of untrusted input in Chrome Text component allows remote sandbox escape via renderer process

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Leading to Sandbox Escape in Chrome for Android

Mon, 13 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Leading to Sandbox Escape in Chrome for Android

Sun, 12 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Android Causes Possible Sandbox Escape

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Android Causes Possible Sandbox Escape

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation in Chrome Allows Potential Sandbox Escape

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation in Chrome Allows Potential Sandbox Escape

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Sandbox Escape via Unsanitized Text Input in Chrome for Android

Mon, 06 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Sandbox Escape via Unsanitized Text Input in Chrome for Android

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Input Validation Flaw Enables Sandbox Escape in Chrome for Android

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Renderer Process Input Validation Flaw Enables Sandbox Escape in Chrome for Android

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Crafted HTML in Chrome for Android

Sat, 04 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Crafted HTML in Chrome for Android

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via crafted HTML in Android Chrome

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via crafted HTML in Android Chrome

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Input Validation Flaw Allowing Sandbox Escape via Renderer Process in Chrome for Android

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Input Validation Flaw Allowing Sandbox Escape via Renderer Process in Chrome for Android

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via renderer process through insufficient input validation in Chrome for Android

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via renderer process through insufficient input validation in Chrome for Android

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chrome Text Component Input Validation Flaw Enables Sandbox Escape

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Text Component Input Validation Flaw Enables Sandbox Escape

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Insufficient Text Input Validation Enables Renderer Sandbox Escape on Chrome Android

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Insufficient Text Input Validation Enables Renderer Sandbox Escape on Chrome Android

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:42:52.127Z

Reserved: 2026-06-29T23:11:43.409Z

Link: CVE-2026-14106

cve-icon Vulnrichment

Updated: 2026-07-01T15:31:24.924Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation