Skip to content
GoogleCVE-2026-19143

Google Chrome: local attacker could potentially perform a sandbox escape

High8.6CVE-2026-19143 · Published Aug 6, 2026 · updated Aug 8, 2026

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 151.0.7922.109, < 151.0.7922.109151.0.7922.109
Details and references

More Google advisories

All Google
Advisory
Google Chrome: use after free
Critical9.6Aug 6
Google Chrome: use after free
High7.5Aug 6
Google Chrome: improper input validation
High8.3Aug 6
Google Chrome: use after free
Critical9.6Aug 6
Google Chrome: integer overflow
Low3.1Aug 6
Google Chrome: remote code execution
High8.8Aug 6

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.