Junglewise Threat Intelligence

CVE-2026-11295: Google Chrome WebView privilege escalation on Android

CVE-2026-11295 · Severity: info · CVSS 3.3 · Published 2026-06-05

Technologies: Google Chrome WebView, Google WebView. Vendors: Google.

Executive brief

A vulnerability in the Android WebView component of Google Chrome could allow a malicious website to gain higher-than-intended permissions. WebView is the technology that allows Android applications to display web content directly within the app. If exploited, an attacker could potentially bypass security boundaries to access data or perform actions they should not be authorized to do.

Technical details

A privilege escalation vulnerability exists in Google Chrome's WebView component for Android due to an inappropriate implementation of security controls. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escalate privileges within the context of the application using WebView. The vulnerability is rated as Low severity by Chromium and was addressed in version 149.0.7827.53.

Affected products

  • Google Chrome WebView prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel.
  • 2026-06-05: disclosed: NVD publication date.

References

Related threats