Google Chromium: 11 CVEs Disclosed Together, Affecting iOS and Android Chrome Versions
Eleven CVEs for Google Chromium were disclosed on July 30, 2026, impacting Chrome on iOS and Android, with severities ranging from Low to High.
Key findings
- Eleven CVEs for Google Chromium disclosed simultaneously on July 30, 2026.
- Vulnerabilities affect Chrome on both iOS and Android platforms.
- Key issues include UI spoofing, navigation bypass, and potential sandbox escapes.
- CVE-2026-17681 is a High-severity flaw with potential sandbox escape capabilities.
- All issues are fixed in Chromium version 151.0.7922.72.
On July 30, 2026, a batch of eleven Common Vulnerabilities and Exposures (CVEs) were disclosed for Google's Chromium, affecting various versions of Chrome on iOS and Android. These vulnerabilities, all published within a two-minute window, range in severity from Low to High, with the most critical flaw, CVE-2026-17681, posing a potential sandbox escape risk. The disclosures highlight ongoing security challenges in complex browser environments.
Several vulnerabilities stem from an "inappropriate implementation" in Chrome for iOS. CVE-2026-17842 and CVE-2026-17941, both rated Medium and Low respectively, allowed for bypassing the same-origin policy and spoofing the Omnibox (URL bar) through crafted HTML or network traffic. Another set of issues, including CVE-2026-17944 (Low), CVE-2026-18003 (Low), and CVE-2026-17960 (Low), involved bypassing navigation restrictions or no-referrer policies via malicious web pages.
On the Android side, vulnerabilities were found in WebView and Media components. CVE-2026-17915 (Low) permitted UI spoofing through crafted HTML in the WebView component. Similarly, CVE-2026-17994 (Low) allowed remote attackers to bypass navigation restrictions in the Media component.
A significant concern arises from two vulnerabilities involving "insufficient validation of untrusted input." CVE-2026-17940 (Low) in the Picture-in-Picture feature and CVE-2026-17681 (High) in Web Authentication, both on Android, could allow a compromised renderer process to potentially escape the sandbox. The latter, rated High, is particularly concerning due to its potential impact.
Additionally, CVE-2026-17952 (Low) in the V8 JavaScript engine allowed for arbitrary code execution within a sandbox via a malicious Chrome Extension, provided the user was convinced to install it.
All eleven vulnerabilities were addressed in Chromium version 151.0.7922.72. Users are strongly advised to ensure their Chrome browsers on both iOS and Android are updated to this version or later to mitigate the risks associated with these security flaws. The coordinated disclosure of these CVEs underscores the importance of timely patching to protect against potential exploitation.
The batch of vulnerabilities disclosed on July 30, 2026, for Google Chromium highlights the persistent challenges in securing complex web browsers. The range of issues, from UI spoofing to potential sandbox escapes, demonstrates the multifaceted nature of browser security. Users are urged to maintain up-to-date browser versions to protect against these threats. The coordinated disclosure of these eleven CVEs emphasizes the ongoing need for vigilance in the cybersecurity landscape.