What is CVE-2026-17681?
CVE-2026-17681 is a vulnerability in the Web Authentication component of Google Chrome on Android. Due to insufficient input validation, a remote attacker who compromised the renderer process could potentially escape the sandbox via a crafted HTML page. Users should update Chrome to version 151.0.7922.72 or later to mitigate this high-severity issue.
Azərbaycanca: CVE-2026-17681 Google Chrome-un Android versiyasında Web Authentication komponentində zəiflikdir. Bu, uzaqdan hücumçuya renderer prosesini ələ keçirdikdən sonra zərərli HTML səhifə vasitəsilə sandbox mühitindən çıxmağa imkan verir. Təsirə məruz qalmamaq üçün Chrome brauzerini 151.0.7922.72 və ya daha yuxarı versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-20; shared vendor: Google
FAQ2
To which version should I update Google Chrome on Android to protect against CVE-2026-17681?
You should update Google Chrome to version 151.0.7922.72 or later to mitigate this vulnerability.
What can an attacker achieve by exploiting CVE-2026-17681?
After compromising the renderer process, the attacker could potentially escape the sandbox via a crafted HTML page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.