CVE-2026-16419
A critical flaw in Google Chrome for Android allows attackers to read and write memory outside intended bounds, potentially escaping the browser sandbox. The vulnerability is triggered by a specially crafted HTML page and could let a remote attacker gain full control of the device. It affects Chrome versions before 150.0.7871.182.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Google Chrome on Android, versions earlier than 150.0.7871.182.
Real-world impact
An attacker could use a malicious web page to read sensitive data, modify memory, and escape the browser sandbox, potentially taking full control of the device.
Why this severity
The CVSS score of 9.6 reflects that the flaw is exploitable over the network (AV:N), requires no user interaction beyond opening a page (UI:R), has no authentication or privilege needed (PR:N), and can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H).
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 21, 2026 · 11d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 8d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- chromereleases.googleblog.com/2026/07/stable-channel-upda…release notesvendor advisory
- issues.chromium.org/issues/523435970permissions required