Description
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-01
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Google's Dawn rendering engine on Android (CWE‑20) enables a remote attacker, who has already compromised the renderer process, to load a specially crafted HTML page that may escape the browser sandbox. The escape could elevate the attacker’s privileges beyond the renderer’s restricted domain, potentially allowing compromise of other applications on the device. The vulnerability does not provide a direct code execution path from an external host; it requires prior compromise of the renderer process.

Affected Systems

Google Chrome on Android versions earlier than 150.0.7871.46 are affected. Only builds before this patch contain the vulnerable Dawn code; newer releases include the fix.

Risk and Exploitability

The CVSS score of 8.3 denotes high severity, while the EPSS score of < 1 % suggests a low likelihood of current exploitation. The flaw requires an attacker to first compromise the renderer process, limiting direct exploitation opportunities. The vulnerability is not listed in the CISA KEV catalog. Attackers who succeed in compromising the renderer can pivot to escape the sandbox, thereby jeopardizing device security.

Generated by OpenCVE AI on July 21, 2026 at 13:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.46 or later to apply the vendor patch.
  • Audit or restrict third‑party extensions and plugins that can inject arbitrary HTML into the renderer to reduce indirect exploitation risk.
  • Monitor Chrome’s renderer process for abnormal activity; if suspicious behavior is detected, isolate or uninstall the affected Chrome installation until a patched version is available.

Generated by OpenCVE AI on July 21, 2026 at 13:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome's Dawn Engine Leading to Sandbox Escape

Fri, 17 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Rendering Engine Vulnerability Allows Sandbox Escape via Crafted HTML

Tue, 14 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Rendering Engine Vulnerability Allows Sandbox Escape via Crafted HTML

Mon, 13 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Invalidation Enables Sandbox Escape in Chrome Android Renderer

Sun, 12 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Invalidation Enables Sandbox Escape in Chrome Android Renderer

Fri, 10 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Input Validation Flaw Permits Sandbox Escape via Crafted HTML

Thu, 09 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Input Validation Flaw Permits Sandbox Escape via Crafted HTML

Thu, 09 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Sandbox escape via crafted HTML due to input validation flaw in Chrome Dawn

Wed, 08 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Sandbox escape via crafted HTML due to input validation flaw in Chrome Dawn

Mon, 06 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Dawn Engine Enables Renderer Sandbox Escape

Mon, 06 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Dawn Engine Enables Renderer Sandbox Escape

Sun, 05 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Input Validation Failure in Chrome Android Dawn Engine Enables Potential Sandbox Escape from Compromised Renderer

Sun, 05 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Input Validation Failure in Chrome Android Dawn Engine Enables Potential Sandbox Escape from Compromised Renderer

Sat, 04 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome's Dawn Engine Enables Sandbox Escape

Fri, 03 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome's Dawn Engine Enables Sandbox Escape

Fri, 03 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Renderer Input Validation Failure in Chrome Android Enabling Sandbox Escape

Fri, 03 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Renderer Input Validation Failure in Chrome Android Enabling Sandbox Escape

Thu, 02 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chrome Android Renderer Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Chrome Android Renderer Sandbox Escape via Crafted HTML

Thu, 02 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-03T03:55:41.885Z

Reserved: 2026-07-01T21:37:34.935Z

Link: CVE-2026-14428

cve-icon Vulnrichment

Updated: 2026-07-02T00:07:17.693Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T13:15:05Z

Weaknesses
  • CWE-20

    Improper Input Validation