Executive brief
A vulnerability in the WebView component of Google Chrome on Android could allow a malicious website to access data from other websites. WebView is a system component that allows Android apps to display web content; an exploit could lead to the unauthorized disclosure of sensitive user information or session data. Users should update their Chrome application to the latest version to mitigate this risk.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the WebView component of Google Chrome for Android. The flaw allows a remote attacker to bypass Same-Origin Policy (SOP) restrictions and leak cross-origin data. An attacker could exploit this by enticing a user to visit a specially crafted HTML page. The vulnerability is addressed in version 149.0.7827.53 and later. The Chromium team has assigned this a security severity of Medium.
Affected products
- Google Chrome for Android WebView prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: NVD publication date