Executive brief
A vulnerability in Google Chrome for Android could allow a malicious website to bypass security protections. By tricking a user into visiting a specially crafted webpage, an attacker who has already gained limited control over the browser's rendering process could escape the 'sandbox'—a security layer designed to keep web content isolated from the rest of the device. This could lead to broader access to the user's device and data.
Technical details
A use-after-free (UAF) vulnerability exists in the WebShare component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the execution of web sharing operations. An attacker who has already compromised the renderer process (typically via a separate vulnerability) can exploit this issue by enticing a user to visit a malicious HTML page. Successful exploitation allows the attacker to perform a sandbox escape, potentially leading to arbitrary code execution outside of the browser's restricted environment. The issue is fixed in version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: CVE published