Executive brief
A vulnerability in Google Chrome for Android's WebView component could allow a malicious website to access data from other websites. This occurs when a user visits a specially crafted page, potentially leading to the exposure of sensitive information across different web domains. Google has released an update to address this issue.
Technical details
An improper input validation vulnerability (CWE-20) exists in the WebView component of Google Chrome for Android. The flaw allows a remote attacker who has already achieved compromise of the renderer process to bypass cross-origin isolation. By enticing a user to load a crafted HTML page, the attacker can leak data from different origins. This issue was addressed in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for stable channel
- 2026-06-04: disclosed: CVE-2026-11007 published