VYPR
Vypr IntelligenceAI-generatedJul 30, 2026· 25 CVEs

Google Chrome on Android: 25 Vulnerabilities Disclosed in Single Batch, Fixed in v151.0.7922.72

Google Chrome on Android: 25 vulnerabilities disclosed on July 30, 2026, impacting UI, sandbox, and data security, all fixed in v151.0.7922.72.

Key findings

  • 25 vulnerabilities disclosed simultaneously for Google Chrome on Android on July 30, 2026.
  • High-severity flaws include potential sandbox escapes and UI spoofing.
  • All issues are fixed in Chrome on Android version 151.0.7922.72.
  • Vulnerabilities affect diverse components including UI, WebView, WebGL, and more.
  • Patching is crucial to mitigate risks of data leakage and UI manipulation.

On July 30, 2026, a significant batch of 25 vulnerabilities was disclosed for Google Chrome on Android, all fixed in version 151.0.7922.72. These vulnerabilities span various components of the browser, including UI, WebView, WebGL, and more, with reported severities ranging from Low to High. The disclosures highlight potential risks such as UI spoofing, navigation restriction bypasses, data leakage, and sandbox escapes.

Several vulnerabilities fall under the category of "Inappropriate implementation" across different modules. CVE-2026-17938, CVE-2026-17961, CVE-2026-17980, CVE-2026-17731, CVE-2026-17915, CVE-2026-17984, CVE-2026-17994, CVE-2026-18007, and CVE-2026-17793 all relate to inappropriate implementations in areas like FullScreen, Session, UI, Autofill, WebView, Browser, Media, Input, and Messages, respectively. These collectively could lead to UI spoofing, navigation bypasses, or cross-origin data leaks.

High-severity flaws include CVE-2026-17722, an object lifecycle issue in WebView that could allow for a sandbox escape. CVE-2026-17690, an insufficient validation of untrusted input in PDF, and CVE-2026-17698, an insufficient validation of untrusted input in UI, are also high-severity, potentially allowing local attackers to leak cross-origin data. Additionally, CVE-2026-17681, an insufficient validation of untrusted input in Web Authentication, presents a risk of sandbox escape.

Medium-severity vulnerabilities include CVE-2026-17808 and CVE-2026-17949, both related to Uninitialized Use in WebGL and GPU respectively, which could lead to cross-origin data leaks. CVE-2026-17733 in QUIC, CVE-2026-17866 in Tab (Type Confusion), CVE-2026-17860 and CVE-2026-17794 in Mobile (Insufficient validation of untrusted input), CVE-2026-17802 in GPU (Side-channel information leakage), and CVE-2026-17872 (Cryptographic Flaw in WebAppInstalls) also contribute to the risk of data leakage or other security compromises.

The batch also includes vulnerabilities related to insufficient policy enforcement in USB (CVE-2026-18000) and WebView (CVE-2026-17953), and a race condition in PictureInPicture (CVE-2026-17999) which could lead to domain spoofing.

All 25 vulnerabilities were addressed in Chrome on Android version 151.0.7922.72. Users are strongly advised to update to this version to mitigate the risks associated with these security flaws. The coordinated disclosure on a single day indicates a focused effort to address these issues by the Chromium security team.

The sheer number of vulnerabilities disclosed simultaneously underscores the importance of regular updates for Google Chrome on Android. While many of these issues are rated as Low or Medium, the presence of High-severity flaws, including potential sandbox escapes and UI spoofing, necessitates prompt patching. Users should ensure their browsers are updated to the latest version to protect against potential exploitation.

The vulnerabilities disclosed include:

The fixed version for all these issues is 151.0.7922.72.

CVE-2026-17938, CVE-2026-17961, CVE-2026-17722, CVE-2026-17808, CVE-2026-17980, CVE-2026-17731, CVE-2026-18000, CVE-2026-17690, CVE-2026-17733, CVE-2026-17698, CVE-2026-17866, CVE-2026-17860, CVE-2026-17915, CVE-2026-17984, CVE-2026-17794, CVE-2026-17994, CVE-2026-17681, CVE-2026-17904, CVE-2026-17999, CVE-2026-18007, CVE-2026-17802, CVE-2026-17793, CVE-2026-17953, CVE-2026-17949, CVE-2026-17872

AI-written article. Grounded in 25 CVE records listed below.