Junglewise Threat Intelligence

CVE-2026-11167: Google Chrome for Android sandbox escape in WebView

CVE-2026-11167 · Severity: info · Published 2026-06-04

Technologies: Google Chrome for Android, Google Chrome, Google WebView. Vendors: Google.

Executive brief

A vulnerability in Google Chrome and WebView on Android could allow a malicious website to escape the browser's security sandbox. This sandbox is designed to keep web content isolated from the rest of the device; if bypassed, an attacker who has already compromised the browser's rendering process could potentially gain broader access to the underlying operating system. This could lead to unauthorized access to device data or further system compromise.

Technical details

This vulnerability is classified as an 'Inappropriate Implementation' within the WebView component of Google Chrome for Android. The flaw allows a remote attacker to perform a sandbox escape, provided they have already achieved a compromise of the renderer process (typically through a separate vulnerability). The attack is executed via a specially crafted HTML page. By escaping the sandbox, the attacker moves from the restricted rendering environment to the more privileged browser process or the Android operating system. The issue is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome for Android prior to 149.0.7827.53
  • Google WebView for Android prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: NVD publication date

References

Related threats