CVE-2026-19143
Description
A flaw was found in Google Chrome on Android. This vulnerability, related to insufficient validation of untrusted input in WebAPKs, allows a local attacker to perform a sandbox escape. By crafting and using a malicious file, an attacker can bypass security restrictions designed to isolate applications, potentially leading to unauthorized access or control over the device.
Statement
This is an Important vulnerability. Insufficient input validation in the WebAPK component of Chromium could allow a local attacker to escape the browser's sandbox by processing a specially crafted malicious file. While the original report references Google Chrome on Android, the underlying flaw affects the Chromium package in Red Hat Community Projects, potentially leading to a compromise of the system beyond the browser's security boundaries.
Understanding the Weakness (CWE)
Other
Technical Impact: Varies by Context
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.