Executive brief
A vulnerability in Google Chrome and WebView on Android could allow a malicious website to escape the browser's security sandbox. This sandbox is designed to keep web content isolated from the rest of the device; if bypassed, an attacker who has already compromised the browser's rendering process could potentially gain broader access to the underlying operating system. This could lead to unauthorized access to device data or further system compromise.
Technical details
This vulnerability is classified as an 'Inappropriate Implementation' within the WebView component of Google Chrome for Android. The flaw allows a remote attacker to perform a sandbox escape, provided they have already achieved a compromise of the renderer process (typically through a separate vulnerability). The attack is executed via a specially crafted HTML page. By escaping the sandbox, the attacker moves from the restricted rendering environment to the more privileged browser process or the Android operating system. The issue is addressed in version 149.0.7827.53.
Affected products
- Google Chrome for Android prior to 149.0.7827.53
- Google WebView for Android prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: NVD publication date