Sceawere

Vulnerability Detail

CVE-2026-19143UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome WebAPK Sandbox Escape

Vulnerability Metadata

Severity
High
Score / CVSS
8.6
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Insufficient validation of untrusted input
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.6",
  "pubDate": "2026-08-06T22:16:56.423Z",
  "pubdate": "2026-08-06T22:16:56.423Z",
  "executiveSummary": "A high-severity security vulnerability involving insufficient validation of untrusted input exists within WebAPKs in Google Chrome on Android prior to version 151.0.7922.109.\nThis vulnerability enables a local attacker to potentially achieve a sandbox escape by leveraging a malicious file.\nThe affected product is Google Chrome on Android, specifically impacting the WebAPK subsystem where proper input sanitization and validation checks were omitted.\nSuccessful exploitation of this flaw allows a malicious actor with local system access to break out of the application's security sandbox, potentially compromising the underlying operating system integrity and accessing unauthorized device resources.\nThe risk implications are significant because sandbox escapes undermine the foundational isolation model of the browser, exposing users to privilege escalation and further system-level compromise.\nAttacker capabilities require local execution context on the targeted Android device, specifically involving the provisioning or manipulation of a malicious file that interacts with vulnerable WebAPK processing logic.\nNo specific remote network vector is required, as the exploitation vector relies entirely on local file handling and input processing weaknesses within the browser architecture.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient validation of untrusted input processed by the WebAPKs component within Google Chrome on Android prior to version 151.0.7922.109.\nWebAPKs allow Progressive Web Apps (PWAs) to be installed as native-like applications on Android, involving complex interactions between the browser engine, Android package management, and local file processing mechanisms.\nWhen processing untrusted input derived from local files, the vulnerable component fails to adequately sanitize, type-check, or bound-check the data before passing it to internal processing routines.\nAn attacker exploits this vulnerability by supplying a specifically crafted malicious file designed to trigger parsing anomalies, memory corruption, or logic flaws during WebAPK handling.\nThe step-by-step attack flow begins with the local attacker placing or delivering the malicious file onto the target Android device.\nNext, the attacker induces Google Chrome or the WebAPK subsystem to process the malicious file, either through direct interaction or by leveraging inter-process communication mechanisms exposed by the browser.\nDue to the absence of rigorous input validation, the malicious input is mishandled by the vulnerable component, leading to memory safety violations or logic bypasses.\nThese execution anomalies are subsequently leveraged to compromise the security boundaries enforced by the application sandbox.\nUpon successful sandbox escape, the attacker gains elevated execution capabilities outside the restricted browser sandbox environment.\nThe vulnerable component is the WebAPK implementation within Google Chrome on Android.\nAffected versions include all Google Chrome on Android builds preceding 151.0.7922.109.\nAuthentication requirements are nonexistent as the vulnerability is triggered locally via file processing.\nPrivilege requirements are minimal, requiring only local access to place and process the malicious file within the context of the device.\nNetwork exposure is local-only, meaning the attack surface relies strictly on local file vectors rather than remote network interfaces."
}
CVE-2026-19143: Google Chrome WebAPK Sandbox Escape (HIGH Severity, CVSS: 8.6) - Sceawere