Executive brief
A vulnerability exists in the WebView component of Google Chrome for Android, which is used by many mobile apps to display web content. A local attacker could use a specially crafted file to cause the application to crash or become unresponsive. This primarily impacts the availability of the affected app rather than compromising user data.
Technical details
An integer overflow vulnerability exists in the WebView component of Google Chrome for Android in versions prior to 149.0.7827.53. The flaw is triggered when the component processes a malicious file, leading to a denial of service (application crash). The vulnerability is categorized under CWE-472 (External Control of Assumed-Immutable Web Parameter) by the vendor. Exploitation requires a local attacker to provide a malicious file to the system, typically requiring some level of user interaction. Google has addressed this issue in the stable channel update for Chrome 149.
Affected products
- Google Chrome WebView prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 promoted to stable channel
- 2026-06-05: disclosed: CVE published to NVD