Junglewise Threat Intelligence

CVE-2026-11097: Google Chrome WebView cross-origin data leak on Android

CVE-2026-11097 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome for Android, Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the WebView component of Google Chrome on Android could allow a malicious website to access data from other websites. WebView is a system component that allows Android apps to display web content. If a user visits a specially crafted webpage, an attacker could potentially leak sensitive information across different web origins, compromising user privacy.

Technical details

A cross-origin data leak vulnerability exists in the WebView component of Google Chrome for Android. The flaw stems from an inappropriate implementation that fails to properly enforce origin boundaries when processing certain web content. A remote attacker can exploit this by enticing a user to visit a maliciously crafted HTML page. Successful exploitation allows the attacker to bypass Same-Origin Policy (SOP) restrictions and leak data from other origins. This issue is addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome for Android prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: CVE published by NVD

References

Related threats