Junglewise Threat Intelligence

CVE-2026-11072: Google Chrome WebView use after free in Android

CVE-2026-11072 · Severity: info · CVSS 6.5 · Published 2026-06-04

Technologies: Google Chrome WebView, Google WebView. Vendors: Google.

Executive brief

A vulnerability exists in the WebView component of Google Chrome for Android, which is used by many mobile apps to display web content. A local attacker could use a specially crafted malicious file to execute unauthorized code on the device. This could lead to a compromise of the application's data or unauthorized access to device resources.

Technical details

A use-after-free (UAF) vulnerability exists in the WebView component of Google Chrome for Android prior to version 149.0.7827.53. The flaw is triggered when the application improperly manages memory during the processing of a malicious file. A local attacker can exploit this by enticing a user or another process to open a specifically crafted file, leading to arbitrary code execution within the context of the application using WebView. This issue is tracked as CWE-416 and has been addressed in the stable channel update for Chrome 149.

Affected products

  • Google Chrome WebView prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 promoted to stable channel
  • 2026-06-04: disclosed: CVE published in NVD

References

Related threats