Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19143

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

A flaw was found in Google Chrome on Android. This vulnerability, related to insufficient validation of untrusted input in WebAPKs, allows a local attacker to perform a sandbox escape. By crafting and using a malicious file, an attacker can bypass security restrictions designed to isolate applications, potentially leading to unauthorized access or control over the device.

Отчет

This is an Important vulnerability. Insufficient input validation in the WebAPK component of Chromium could allow a local attacker to escape the browser's sandbox by processing a specially crafted malicious file. While the original report references Google Chrome on Android, the underlying flaw affects the Chromium package in Red Hat Community Projects, potentially leading to a compromise of the system beyond the browser's security boundaries.

Дополнительная информация

Статус:

Important
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2512303chromium-browser: Google Chrome on Android: Sandbox escape via malicious WebAPK input

EPSS

Процентиль: 2%
0.00115
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
10 дней назад

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVSS3: 8.6
nvd
10 дней назад

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

CVSS3: 8.6
debian
10 дней назад

Insufficient validation of untrusted input in WebAPKs in Google Chrome ...

CVSS3: 8.6
github
10 дней назад

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

suse-cvrf
6 дней назад

Security update for chromium

EPSS

Процентиль: 2%
0.00115
Низкий

8.2 High

CVSS3