Description
Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An input validation flaw in the Text component of Google Chrome for Android allowed an attacker who had already compromised the renderer process to supply a crafted HTML page that could escape the sandbox, potentially allowing the execution of arbitrary code with elevated privileges on the device. The weakness is classified as CWE-20, Improper Input Validation.

Affected Systems

All Android installations of Google Chrome earlier than version 150.0.7871.47 are vulnerable.

Risk and Exploitability

The EPSS score is less than 1% and the CVSS score of 9.6 indicates a high severity, yet the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly documented exploitation. The attack requires an attacker to first gain control of the renderer process, which is a significant prerequisite; thus the likelihood of exploitation is low. If successful, the attacker could escape the sandbox and elevate privileges on the victim device, making the potential impact severe.

Generated by OpenCVE AI on July 21, 2026 at 15:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to apply the vendor fix
  • Remove or block any older Chrome installations that are not patched from being used on the device
  • Configure Chrome’s enterprise policy to restrict loading of untrusted content, preventing crafted HTML from being processed by a compromised renderer

Generated by OpenCVE AI on July 21, 2026 at 15:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Android Text Component Could Enable Sandbox Escape

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Insufficient validation of untrusted input in Chrome Text component allows remote sandbox escape via renderer process

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Insufficient validation of untrusted input in Chrome Text component allows remote sandbox escape via renderer process

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Leading to Sandbox Escape in Chrome for Android

Mon, 13 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Leading to Sandbox Escape in Chrome for Android

Sun, 12 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Android Causes Possible Sandbox Escape

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Android Causes Possible Sandbox Escape

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation in Chrome Allows Potential Sandbox Escape

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation in Chrome Allows Potential Sandbox Escape

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Sandbox Escape via Unsanitized Text Input in Chrome for Android

Mon, 06 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Sandbox Escape via Unsanitized Text Input in Chrome for Android

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Input Validation Flaw Enables Sandbox Escape in Chrome for Android

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Renderer Process Input Validation Flaw Enables Sandbox Escape in Chrome for Android

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Crafted HTML in Chrome for Android

Sat, 04 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Sandbox Escape via Crafted HTML in Chrome for Android

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via crafted HTML in Android Chrome

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via crafted HTML in Android Chrome

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Input Validation Flaw Allowing Sandbox Escape via Renderer Process in Chrome for Android

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Input Validation Flaw Allowing Sandbox Escape via Renderer Process in Chrome for Android

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via renderer process through insufficient input validation in Chrome for Android

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Remote sandbox escape via renderer process through insufficient input validation in Chrome for Android

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chrome Text Component Input Validation Flaw Enables Sandbox Escape

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Text Component Input Validation Flaw Enables Sandbox Escape

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Insufficient Text Input Validation Enables Renderer Sandbox Escape on Chrome Android

Wed, 01 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Insufficient Text Input Validation Enables Renderer Sandbox Escape on Chrome Android

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:42:52.127Z

Reserved: 2026-06-29T23:11:43.409Z

Link: CVE-2026-14106

cve-icon Vulnrichment

Updated: 2026-07-01T15:31:24.924Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:45:08Z

Weaknesses
  • CWE-20

    Improper Input Validation