Description
Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in the ANGLE graphics layer of Google Chrome for Android before 150.0.7871.46 allows a remote attacker who has first compromised the renderer process to trigger a sandbox escape by serving a specially crafted HTML page. This flaw, a classic input‑validation defect (CWE‑20), could let attacker escape from the renderer sandbox to the host system, potentially granting unauthorized access to local files or system resources.

Affected Systems

Google Chrome for Android versions earlier than 150.0.7871.46, which include the ANGLE component used for graphics rendering, are vulnerable. Any device running those versions and loading a malicious page after a renderer compromise is at risk.

Risk and Exploitability

Exploitation requires a prior compromise of the renderer process, and based on the description, it is inferred that a separate vulnerability is needed. Once the renderer is under attacker control, delivering a crafted HTML page exploits the input‑validation bug and can result in a sandbox escape. The EPSS score of < 1 % indicates a low probability of exploitation in the wild, but the CVSS score of 8.3 signals a high potential impact if the conditions are met. The flaw is not listed in the CISA KEV catalog, so there are currently no publicly known active exploits.

Generated by OpenCVE AI on July 21, 2026 at 13:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome for Android to version 150.0.7871.46 or later
  • Ensure that Chrome is automatically updated via Google Play Services or the device’s update channel to receive timely patches
  • If immediate update is not possible, restrict the renderer’s access to system resources by configuring Chrome’s sandbox settings or using enterprise policy to limit filesystem visibility

Generated by OpenCVE AI on July 21, 2026 at 13:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Leading to Potential Sandbox Escape in Chrome for Android

Thu, 16 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Failure Enables Sandbox Escape in Chrome Android

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Failure Enables Sandbox Escape in Chrome Android

Mon, 13 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Defect in Chrome on Android Leading to Sandbox Escape

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Defect in Chrome on Android Leading to Sandbox Escape

Sun, 12 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Flaw allows Sandbox Escape in Chrome for Android

Sat, 11 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Flaw allows Sandbox Escape in Chrome for Android

Fri, 10 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Leading to Potential Sandbox Escape in Chrome for Android

Thu, 09 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Leading to Potential Sandbox Escape in Chrome for Android

Wed, 08 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Vulnerability Enables Sandbox Escape in Chrome for Android

Tue, 07 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Vulnerability Enables Sandbox Escape in Chrome for Android

Mon, 06 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Vulnerability Enables Sandbox Escape on Android Chrome

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Vulnerability Enables Sandbox Escape on Android Chrome

Sun, 05 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Exploit Leading to Sandbox Escape in Chrome for Android

Sun, 05 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Exploit Leading to Sandbox Escape in Chrome for Android

Sat, 04 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome Android ANGLE Sandbox Escape via Malicious HTML Page

Sat, 04 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Chrome Android ANGLE Sandbox Escape via Malicious HTML Page

Sat, 04 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Bug Allowing Sandbox Escape in Chrome for Android

Fri, 03 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Bug Allowing Sandbox Escape in Chrome for Android

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Flaw Enables Sandbox Escape in Chrome for Android

Thu, 02 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title ANGLE Input Validation Flaw Enables Sandbox Escape in Chrome for Android

Thu, 02 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome on Android ANGLE Input Validation Flaw Enabling Sandbox Escape

Thu, 02 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome on Android ANGLE Input Validation Flaw Enabling Sandbox Escape

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:44.026Z

Reserved: 2026-07-01T21:37:28.739Z

Link: CVE-2026-14401

cve-icon Vulnrichment

Updated: 2026-07-02T00:07:24.612Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation