CVE-2026-19143

Description

A flaw was found in Google Chrome on Android. This vulnerability, related to insufficient validation of untrusted input in WebAPKs, allows a local attacker to perform a sandbox escape. By crafting and using a malicious file, an attacker can bypass security restrictions designed to isolate applications, potentially leading to unauthorized access or control over the device.

Statement

This is an Important vulnerability. Insufficient input validation in the WebAPK component of Chromium could allow a local attacker to escape the browser's sandbox by processing a specially crafted malicious file. While the original report references Google Chrome on Android, the underlying flaw affects the Chromium package in Red Hat Community Projects, potentially leading to a compromise of the system beyond the browser's security boundaries.

Understanding the Weakness (CWE)

Other

Technical Impact: Varies by Context

Frequently Asked Questions

Want to get errata notifications? Sign up here.